Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-47706

Strawberry GraphQL has a Circular Fragment Reference DOS_CVE-2026-47706

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an ...

strawberry-graphql strawberry >= 0.71.0, < 0.315.7 CVE
MEDIUM 5.3 CVE-2026-10864

MISP Dashboard widget field selection may expose restricted user and organisation data_CVE-2026-10864

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returne...

misp misp CVE
MEDIUM 6.4 CVE-2026-10863

MISP User-controlled order parameter in correlations over-correlation endpoint_CVE-2026-10863

A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named re...

misp misp CVE
MEDIUM 5.3 CVE-2026-10811

itsourcecode Fees Management System receipt.php sql injection_CVE-2026-10811

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality o...

itsourcecode Fees Management System 1.0 CVE
MEDIUM 6.5 CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509_CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused stri...

Go standard library crypto/x509 CVE
MEDIUM 5.3 CVE-2026-49077

WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability_CVE-2026-49077

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded ...

Tips and Tricks HQ WP eMember n/a CVE
MEDIUM 5.3 CVE-2026-10802

keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption_CVE-2026-10802

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/co...

keystonejs keystone 20260319 CVE
MEDIUM 4.3 CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. ._CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic...

HCL iControl 4.0.0 CVE
MEDIUM 6.1 CVE-2026-8916

CVE-2026-8916_CVE-2026-8916

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd...

Samsung Open Source rlottie dcfde72eae1b0464dc0dd760aec00ada6a148635 CVE
MEDIUM 6.9 CVE-2026-50226

Firmware Theft & IMEI Spoofing via Connect-OTA_CVE-2026-50226

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows...

Acer Connect M6E 5G Portable WiFi Router * CVE