Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-45570

go-git: Improper single-quote escaping in go-git SSH transport_CVE-2026-45570

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the rem...

go-git go-git < 5.19.1 CVE
LOW 3.7 CVE-2026-44474

Ella Core: Handover failures during concurrent Security Mode Command_CVE-2026-44474

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security pr...

ellanetworks core < 1.10.0 CVE
LOW 3.7 CVE-2026-42082

free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover_CVE-2026-42082

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security proced...

free5gc free5gc < 4.2.2 CVE
LOW 3.3 CVE-2026-39824

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows_CVE-2026-39824

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 1...

golang.org/x/sys golang.org/x/sys/windows CVE
LOW 3.5 CVE-2026-42448

wormhole receive, with –output pointing at an existing directory can be path-traversed_CVE-2026-42448

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traver...

magic-wormhole magic-wormhole < 0.24.0 CVE
LOW 2.3 CVE-2026-9568

ThingsBoard YAML provision getGatewayDockerComposeFile code injection_CVE-2026-9568

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file...

n/a ThingsBoard 4.3.1.0 CVE
LOW 3.1 CVE-2026-47716

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known_CVE-2026-47716

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in th...

bugsink bugsink < 2.2.0 CVE
LOW 3.1 CVE-2026-47715

Bugsink: Issue event views can show an event from another project if its UUID is known_CVE-2026-47715

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affec...

bugsink bugsink < 2.2.0 CVE
LOW 3.8 CVE-2026-44410

Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE_CVE-2026-44410

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviati...

ZTE ZXUniPOS NDS-LTE V24.40.40 CVE
LOW 1.8 CVE-2025-71310

CVE-2025-71310_CVE-2025-71310

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious ...

BackdropCMS GDPR cookies module for Backdrop CMS CVE