Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8 CVE-2026-48163

MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)_CVE-2026-48163

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.27 CVE
HIGH 7.8 CVE-2026-47965

Acrobat Reader | Out-of-bounds Write (CWE-787)_CVE-2026-47965

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary ...

Adobe Acrobat Reader CVE
HIGH 8.7 CVE-2026-47216

Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint_CVE-2026-47216

Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in t...

typesense typesense < 29.1 CVE
HIGH 8 CVE-2026-44168

MariaDB: wsrep SST unsafe parameter handling on the donor side_CVE-2026-44168

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.26 CVE
HIGH 8.1 CVE-2026-53408

CVE-2026-53408_CVE-2026-53408

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an un...

Zoom Communications Zoom Workplace CVE
HIGH 8.1 CVE-2026-53407

CVE-2026-53407_CVE-2026-53407

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an un...

Zoom Communications Zoom Workplace CVE
HIGH 8.7 CVE-2026-50108

Naxclow IoT Platform Missing Authorization_CVE-2026-50108

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the...

Naxclow Smart Doorbell X3 All CVE
HIGH 8.7 CVE-2026-47138

Parse Server: Pre-authentication denial of service via client version header regex backtracking_CVE-2026-47138

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1,...

parse-community parse-server < 8.6.77 CVE
HIGH 8.7 CVE-2026-42947

Naxclow IoT Platform Authorization bypass through User-Controlled key_CVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an ar...

Naxclow Smart Doorbell X3 All CVE
HIGH 7.2 CVE-2026-42306

Moby: Race condition in docker cp allows bind mount redirection to host path_CVE-2026-42306

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prio...

moby moby github.com/docker/docker/daemon <= 28.5.2 CVE