Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-5066

net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function_CVE-2026-5066

A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c)....

zephyrproject-rtos Zephyr * CVE
MEDIUM 6.3 CVE-2026-42538

IRIS has an Insecure File Upload_CVE-2026-42538

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not ...

dfir-iris iris-web < 2.4.28 CVE
MEDIUM 4.7 CVE-2026-42329

Iris has an Open Redirect issue_CVE-2026-42329

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain...

dfir-iris iris-web < 2.4.28 CVE
MEDIUM 6.6 CVE-2026-48480

netty-incubator-codec-ohttp OHttpVersionChunkDraft’s Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation_CVE-2026-48480

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-...

netty netty-incubator-codec-ohttp < 0.0.22.Final CVE
MEDIUM 5.3 CVE-2026-40898

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion_CVE-2026-40898

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HT...

quic-go quic-go < 0.59.1 CVE
MEDIUM 6.5 CVE-2026-36499

CVE-2026-36499_CVE-2026-36499

A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an ex...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2025-65640

CVE-2025-65640_CVE-2025-65640

Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper san...

n/a n/a n/a CVE
MEDIUM 4.6 CVE-2026-36178

CVE-2026-36178_CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly ...

n/a n/a n/a CVE
MEDIUM 6.8 CVE-2026-36175

CVE-2026-36175_CVE-2026-36175

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interr...

n/a n/a n/a CVE
MEDIUM 6.9 CVE-2026-7774

tarfile.data_filter path traversal bypass allows writing outside the extraction directory_CVE-2026-7774

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive ...

Python Software Foundation CPython CVE