Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 CVE-2026-11800

Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion_CVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client c...

Red Hat Red Hat build of Keycloak 26.6 26.6.4-2 CVE
HIGH 8.1 CVE-2026-22879

CVE-2026-22879_CVE-2026-22879

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

vtk vtk 9.5.2 CVE
HIGH 7.6 CVE-2025-71340

picklescan – Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode_CVE-2025-71340

picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Att...

picklescan picklescan CVE
HIGH 8.6 CVE-2025-71335

Flowise – Session Invalidation Failure After Password Change_CVE-2025-71335

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their pas...

Flowise Flowise CVE
HIGH 8.7 CVE-2025-71328

Flowise – Unverified Password Change via Account Settings_CVE-2025-71328

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the acc...

Flowise Flowise CVE
HIGH 8.7 CVE-2025-71324

Flowise – Arbitrary File Read via chatId Parameter_CVE-2025-71324

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assist...

Flowise Flowise CVE
HIGH 8.8 25DE60F3-D53C-

Exploit for Path Traversal in Tp-Link Tapo_C260_Firmware_25DE60F3-D53C-5F5C-9C45-E27FA387E1AA

Tapo C260 RCE Chain CVE-2026-0651 / CVE-2026-0652 / CVE-2026-0653 Proof-of-concept exploit chain for TP-Link Tapo C260 IP camera achieving unauthen...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2025-61021

CVE-2025-61021_CVE-2025-61021

An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via cr...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61019

CVE-2025-61019_CVE-2025-61019

An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafte...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-12844

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function_CVE-2026-12844

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by...

DROLSKY List::SomeUtils::XS CVE