Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-54220

Cross-Site Request Forgery in UBB.threads_CVE-2026-54220

uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authen...

UBB Systems UBB.threads CVE
HIGH 8.5 CVE-2026-56012

WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability_CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows ...

David Lingren Media LIbrary Assistant n/a CVE
HIGH 7.1 CVE-2026-50141

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation_CVE-2026-50141

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any auth...

woodpecker-ci woodpecker >= 3.0.0, < 3.14.1 CVE
HIGH 8.1 CVE-2026-42488

x86: mismatched mapcache metadata_CVE-2026-42488

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between ...

Xen Xen consult Xen advisory XSA-494 CVE
HIGH 7.9 CVE-2026-42487

x86 HVM I/O port list traversal_CVE-2026-42487

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_...

Xen Xen consult Xen advisory XSA-491 CVE
HIGH 8.4 CVE-2026-46580

CVE-2026-46580_CVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could ...

Eclipse Foundation Eclipse Theia CVE
HIGH 8.4 CVE-2026-44691

CVE-2026-44691_CVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be execute...

Eclipse Foundation Eclipse Theia CVE
HIGH 8.4 CVE-2026-44688

CVE-2026-44688_CVE-2026-44688

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without dis...

Eclipse Foundation Eclipse Theia CVE
HIGH 7.2 CVE-2025-52465

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page_CVE-2025-52465

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists...

geoserver org.geoserver.web:gs-web-app < 2.26.4 CVE
HIGH 7.2 CVE-2025-27511

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection_CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Exte...

geoserver org.geoserver.extension:gs-db2 < 2.27.0 CVE