Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-36670

CVE-2026-36670_CVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows...

OpenSIPS opensips-cp < 9.3.3 CVE
HIGH 7.8 CVE-2026-36213

CVE-2026-36213_CVE-2026-36213

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

n/a n/a n/a CVE
HIGH 8 CVE-2025-68713

CVE-2025-68713_CVE-2025-68713

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows unt...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-12328

Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152_CVE-2026-12328

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs s...

Mozilla Firefox 115.37 CVE
HIGH 8.8 CVE-2026-12289

Privilege escalation in the Graphics: WebRender component_CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
HIGH 8.2 CVE-2026-48780

Forem vulnerable to bypass of email address domain restrictions_CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to byp...

forem forem < a2ab6d4 CVE
HIGH 7.7 CVE-2026-47684

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP_CVE-2026-47684

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP bloc...

Sync-in server < 2.3.0 CVE
HIGH 7.5 CVE-2026-12398

Galaxy_ng: shell injection in legacy role import via unsanitized git ref names_CVE-2026-12398

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitize...

Red Hat Red Hat Ansible Automation Platform 2 CVE
HIGH 8.7 CVE-2026-11317

Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP_CVE-2026-11317

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is se...

Rockwell Automation CompactLogix, ControlLogix Versions prior to 34.016, 35.015, 36.012 CVE
HIGH 8.8 CVE-2026-0647

Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities_CVE-2026-0647

An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated a...

Rockwell Automation FLEX I/O EtherNet/IP Adapters 2.012 CVE