Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-53981

Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism_CVE-2026-53981

Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authentica...

Cap-go Cap-go CVE
HIGH 7.1 CVE-2026-3840

Path Traversal in kedro-org/kedro_CVE-2026-3840

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path...

kedro-org kedro-org/kedro unspecified CVE
HIGH 7.5 CVE-2026-50645

Apache CXF: No restriction on attachment headers per message_CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to unc...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.1 CVE-2026-50633

Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl_CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is ab...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.1 CVE-2026-50632

Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory_CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, w...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 7.4 CVE-2026-50631

Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing_CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate m...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.5 CVE-2026-11967

Arbitrary code execution in MobaXterm Personal Edition (Portable)_CVE-2026-11967

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the ...

Mobatek MobaXterm Personal Edition (Portable) 26.3 CVE
HIGH 8.6 CVE-2026-7368

Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization_CVE-2026-7368

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded crede...

Yarbo Yarbo Android/IOS mobile application CVE
HIGH 8.7 CVE-2026-6211

Arbitrary File Upload in Global IT’s WEOLL_CVE-2026-6211

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Prope...

Global IT Informatics Services Inc. WEOLL 2.0.9 CVE
HIGH 8.8 CVE-2026-53721

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher_CVE-2026-53721

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule...

nuxt nuxt >= 3.11.0, < 3.21.7 CVE