Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-42186

OpenBao’s Namespace Deletion May Not Delete Data Properly_CVE-2026-42186

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent ret...

openbao openbao < 2.5.3 CVE
LOW 3.8 CVE-2026-6923

Nuvoton – CWE-1300: Improper Protection of Physical Side Channels_CVE-2026-6923

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

Nuvoton NPCT7xx all versions below 7.2.4.0 CVE
LOW 2.3 CVE-2026-44515

Nextcloud News: Authenticated blind SSRF via feed URL_CVE-2026-44515

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (...

nextcloud news < 28.3.0-beta.1 CVE
LOW 2.5 CVE-2026-44348

PoDoFo: Double-free vulnerability in compute_hash_to_sign()_CVE-2026-44348

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/...

podofo podofo >= 1.0.0, < 1.0.4 CVE
LOW 2.6 CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters._CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it...

HCL AION 2.1.0 CVE
LOW 2.3 CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured_CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers ...

HCL AION 2.1.0 CVE
LOW 3 CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication_CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may exp...

HCL AION 2.1.0 CVE
LOW 2.6 CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields._CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information...

HCL AION 2.1.0 CVE
LOW 3.7 CVE-2026-6638

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name_CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary S...

n/a PostgreSQL 18 CVE
LOW 3.5 CVE-2026-7471

Server-Side Request Forgery (SSRF) in GitLab_CVE-2026-7471

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 18.8 CVE