Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-40963

Apache Airflow: DAG authorization bypass on /ui/structure/structure_data_CVE-2026-40963

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read...

Apache Software Foundation Apache Airflow 3.0.0 CVE
LOW 2.9 CVE-2026-10532

Logback deserialization whitelist bypass for Proxy objects_CVE-2026-10532

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Objec...

QOS.CH Sarl logback CVE
LOW 3.5 CVE-2026-48191

Wrong Permission Handling in Document Search Article Meta Filters_CVE-2026-48191

An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows ga...

OTRS AG OTRS 7.0.x CVE
LOW 3.5 CVE-2026-48190

Incorrect handling of permissions in External Interface Config Item List module_CVE-2026-48190

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system...

OTRS AG OTRS 7.0.x CVE
LOW 2 CVE-2026-4387

Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file_CVE-2026-4387

StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web ...

StrongDM StrongDM Desktop Application CVE
LOW 3.3 CVE-2026-45613

Rizin: Heap-buffer-overflow in OMF parser_CVE-2026-45613

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vu...

rizinorg rizin < e6d0937c8a083e23ed76ccfb9f631cdc50c7af47 CVE
LOW 3.3 CVE-2026-45324

Rizin: Double free in cmd_search.c_CVE-2026-45324

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cmd_search.c:byte_pattern_sea...

rizinorg rizin < 045fff363b42b8a6dda8ad5229c29ec3267e7dbe CVE
LOW 2.9 CVE-2026-45151

NanoMQ: NULL Pointer Dereference_CVE-2026-45151

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream poin...

nanomq nanomq <= 0.24.8 CVE
LOW 3.1 CVE-2026-9991

CVE-2026-9991_CVE-2026-9991

Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the rendere...

Google Chrome 148.0.7778.216 CVE
LOW 3.1 CVE-2026-9959

CVE-2026-9959_CVE-2026-9959

Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Ch...

Google Chrome 148.0.7778.216 CVE