Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-11251

CVE-2026-11251_CVE-2026-11251

Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rende...

Google Chrome 149.0.7827.53 CVE
LOW 3.1 CVE-2026-11244

CVE-2026-11244_CVE-2026-11244

Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromis...

Google Chrome 149.0.7827.53 CVE
LOW 2 CVE-2026-11329

onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash_CVE-2026-11329

A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/py...

onnx onnx-mlir 0.5.0 CVE
LOW 2.7 CVE-2026-9088

Keycloak: keycloak: information disclosure due to user profile permission bypass_CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permi...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.1 CVE-2026-45287

OpenTelemetry-Go’s Schema ParseFile leaks file descriptors on each parse_CVE-2026-45287

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.i...

open-telemetry go.opentelemetry.io/otel/schema/v1.1 < 0.0.17 CVE
LOW 2 CVE-2026-10814

milvus-io milvus Grantee ID Hash kv_catalog.go weak hash_CVE-2026-10814

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoor...

milvus-io milvus 2.6.0 CVE
LOW 2 CVE-2026-10813

LMCache KV Cache utils.py hex_hash_to_int16 weak hash_CVE-2026-10813

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the comp...

n/a LMCache 0.4.0 CVE
LOW 2.2 CVE-2026-50266

CVE-2026-50266_CVE-2026-50266

In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner...

OpenStack Neutron 25.0.0 CVE
LOW 3.3 CVE-2025-62338

The HCL BigFix Cloud Lifecycle Management is affected by Lack of Input Validation._CVE-2025-62338

The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-...

HCL BigFix Cloud Lifecycle Management 10.9.1 and 10.9.2 CVE
LOW 3.1 CVE-2026-45739

Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs_CVE-2026-45739

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values...

strawberry-graphql strawberry >= 0.288.4, < 0.315.4 CVE