Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2026-11792

389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string)_CVE-2026-11792

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog...

Red Hat Red Hat Directory Server 11 CVE
LOW 1.9 CVE-2026-11786

389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()_CVE-2026-11786

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicol...

Red Hat Red Hat Directory Server 11 CVE
LOW 3.5 CVE-2026-8981

Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML_CVE-2026-8981

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to i...

Unknown Custom Block Builder CVE
LOW 2.1 CVE-2026-49738

TYPO3 CMS – Broken Access Control in File Abstraction Layer_CVE-2026-49738

The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator b...

TYPO3 TYPO3 CMS CVE
LOW 3.6 CVE-2026-11764

Data exposed without proper permission_CVE-2026-11764

When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the expo...

pretix pretix 2024.1.0 CVE
LOW 2.4 CVE-2026-41986

CVE-2026-41986_CVE-2026-41986

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

Huawei HarmonyOS 6.1.0 CVE
LOW 3.6 CVE-2026-41974

CVE-2026-41974_CVE-2026-41974

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

Huawei HarmonyOS 4.3.1 CVE
LOW 3.7 CVE-2026-41852

Spring Framework Arbitrary Method Invocation in SpEL Expressions_CVE-2026-41852

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted ...

Spring Spring Framework 7.0.0 CVE
LOW 3.7 CVE-2026-41848

Spring Framework Denial of Service via AntPathMatcher_CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then d...

Spring Spring Framework 7.0.0 CVE
LOW 2 CVE-2026-11623

tmux image.c image_free use after free_CVE-2026-11623

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to ...

n/a tmux 3.6a CVE