Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2026-49290

Slopsmith has path traversal in archive extractors that allows arbitrary file write → potential RCE_CVE-2026-49290

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a pat...

byrongamatos slopsmith < 0.2.9-alpha.5 CVE
HIGH 7.4 CVE-2026-49287

Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction_CVE-2026-49287

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It a...

statamic cms < 5.73.23 CVE
HIGH 8.1 CVE-2026-49286

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)_CVE-2026-49286

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the...

pontedilana php-weasyprint < 2.6.0 CVE
HIGH 7.1 CVE-2026-49339

Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user’s playlist_CVE-2026-49339

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a...

sentriz gonic < 0.21.0 CVE
HIGH 7.5 CVE-2026-49293

CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals_CVE-2026-49293

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / b...

sunnyadn js-toml < 1.1.1 CVE
HIGH 8.1 CVE-2026-49291

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call_CVE-2026-49291

mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only...

doobidoo mcp-memory-service < 10.65.3 CVE
HIGH 7.5 CVE-2026-9375

Decompression Bomb Bypass via Negative max_length in Streaming API in urllib3_CVE-2026-9375

urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The is...

urllib3 urllib3/urllib3 unspecified CVE
HIGH 8.1 CVE-2026-49340

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host_CVE-2026-49340

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdat...

sentriz gonic < 0.21.0 CVE
HIGH 7.1 CVE-2026-49338

Subsonic API: any authenticated user can delete or read any other user’s playlist (IDOR)_CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/de...

sentriz gonic < 0.21.0 CVE
HIGH 8.1 CVE-2026-56211

Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames_CVE-2026-56211

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encode...

Red Hat Red Hat Enterprise Linux 10 CVE