Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2026-35343

uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters_CVE-2026-35343

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The ...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35342

uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR_CVE-2026-35342

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp w...

Uutils coreutils CVE
LOW 2.7 CVE-2025-9957

Incorrect Authorization in GitLab_CVE-2025-9957

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that ...

GitLab GitLab 11.2 CVE
LOW 3.5 CVE-2026-3254

Improper Restriction of Rendered UI Layers or Frames in GitLab_CVE-2026-3254

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an...

GitLab GitLab 18.11 CVE
LOW 3.7 PACKETSTORM:219545

đź“„ Dovecot 3.1.0 Authentication Bypass / User Enumeration_PACKETSTORM:219545

This Metasploit auxiliary module targets an LDAP injection vulnerability in Dovecot mail servers that can lead to authentication bypass or user enu...

N/A N/A PACKETSTORM
LOW 3.1 CVE-2026-33599

Out-of-bounds read in service discovery_CVE-2026-33599

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) op...

PowerDNS DNSdist 1.9.0 CVE
LOW 3.7 CVE-2026-33597

PRSD detection denial of service_CVE-2026-33597

PRSD detection denial of service

PowerDNS DNSdist 1.9.0 CVE
LOW 3.1 CVE-2026-33596

TCP backend stream ID overflow_CVE-2026-33596

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfect...

PowerDNS DNSdist 1.9.0 CVE
LOW 2.5 CVE-2026-6842

Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions_CVE-2026-6842

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instea...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3.7 CVE-2026-22746

User Attribute Enumeration when Using DaoAuthenticationProvider_CVE-2026-22746

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user at...

Spring Spring Security 5.7.0 CVE