Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability_CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details whi...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.1 CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability_CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, ...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.5 CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation_CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as X...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 2.2 CVE-2026-3109

Missing timestamp validation in Zoom webhook handler_CVE-2026-3109

Mattermost Plugins versions

Mattermost Mattermost CVE
LOW 1.3 CVE-2026-33402

SAK-52311: Sakai site-manage group titles can contain XSS content_CVE-2026-33402

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can cont...

sakaiproject sakai >= 23.0, < 23.5 CVE
LOW 3.7 CVE-2026-33490

h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes_CVE-2026-33490

H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `startsWith()` check to determi...

h3js h3 >= 2.0.1-alpha.0, < 2.0.1-rc.17 CVE
LOW 3.3 CVE-2026-33529

Zoraxy: Authenticated Path Traversal in Config Import leads to RCE_CVE-2026-33529

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the co...

tobychui zoraxy < 3.3.2 CVE
LOW 0.5 CVE-2026-33525

Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting_CVE-2026-33525

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications vi...

authelia authelia = 4.39.15 CVE
LOW 2.3 CVE-2026-33644

Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs_CVE-2026-33644

Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be bypassed using DNS re...

LycheeOrg Lychee < 7.5.2 CVE
LOW 3.3 CVE-2026-2271

Gimp: gimp: denial of service via crafted psp image file_CVE-2026-2271

A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_...

Red Hat Red Hat Enterprise Linux 6 CVE