Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-55202

Tinyproxy – Stathost Detection Bypass via Host Header Manipulation_CVE-2026-55202

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated a...

tinyproxy tinyproxy CVE
HIGH 7.4 CVE-2026-55201

Evil-WinRM – Path Traversal in download_dir() Function_CVE-2026-55201

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or comp...

Hackplayers evil-winrm CVE
HIGH 8.2 CVE-2026-55199

libssh2 – Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler_CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in s...

libssh2 libssh2 CVE
HIGH 7.5 CVE-2026-10696

CVE-2026-10696_CVE-2026-10696

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community cat...

Devolutions UniGetUI CVE
HIGH 8.1 CVE-2026-50107

NGINX Gateway Fabric vulnerability_CVE-2026-50107

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX confi...

F5 NGINX Gateway Fabric 2.3.0 CVE
HIGH 8.6 CVE-2026-11407

Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed_CVE-2026-11407

Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary meth...

Pimcore GmbH Pimcore CMS/DXP CVE
HIGH 7.1 CVE-2026-49133

Typemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia()_CVE-2026-49133

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary f...

typemill typemill CVE
HIGH 7.5 CVE-2026-48979

PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling_CVE-2026-48979

PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 an...

php-standard-library php-standard-library >= 6.1.0, < 6.1.2 CVE
HIGH 8.4 CVE-2025-26240

CVE-2025-26240_CVE-2025-26240

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and t...

n/a n/a n/a CVE
HIGH 7.4 CVE-2026-9697

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent_CVE-2026-9697

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS ...

undici undici 7.23.0 CVE