Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-37453

CVE-2026-37453_CVE-2026-37453

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38637

CVE-2026-38637_CVE-2026-38637

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37452

CVE-2026-37452_CVE-2026-37452

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI...

n/a n/a n/a CVE
HIGH 7.7 CVE-2026-10835

SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection_CVE-2026-10835

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before ...

Unknown SALESmanago & Leadoo CVE
HIGH 7.5 CVE-2026-49486

Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)_CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control...

Apache Software Foundation Apache Airflow FTP provider CVE
HIGH 7.5 CVE-2026-11702

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes_CVE-2026-11702

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before for...

DAVIDO Bytes::Random::Secure::Tiny CVE
HIGH 7.5 CVE-2026-11625

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes_CVE-2026-11625

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, o...

DAVIDO Bytes::Random::Secure CVE
HIGH 7.3 CVE-2026-57915

Apache Kerby: Kerberos Pre-Authentication Bypass_CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users...

Apache Software Foundation Apache Kerby CVE
HIGH 8.5 CVE-2026-57667

WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability_CVE-2026-57667

Sales Representative SQL Injection in Groundhogg

Adrian Tobey Groundhogg n/a CVE
HIGH 8.5 CVE-2026-57663

WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - SQL Injection vulnerability_CVE-2026-57663

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes

Igor Benic Recipe Maker For Your Food Blog from Zip Recipes n/a CVE