Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-42794

Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug_CVE-2026-42794

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scrip...

absinthe-graphql absinthe_plug 1.2.0 CVE
LOW 2.3 CVE-2026-41889

pgx: SQL Injection via placeholder confusion with dollar quoted string literals_CVE-2026-41889

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a doll...

jackc pgx < 5.9.2 CVE
LOW 3.3 CVE-2026-32803

CVE-2026-32803_CVE-2026-32803

Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains a...

Dell PowerScale OneFS CVE
LOW 3 CVE-2026-44916

CVE-2026-44916_CVE-2026-44916

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.

OpenStack Ironic CVE
LOW 2.9 CVE-2026-44928

CVE-2026-44928_CVE-2026-44928

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

uriparser uriparser CVE
LOW 2.9 CVE-2026-44927

CVE-2026-44927_CVE-2026-44927

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

uriparser uriparser CVE
LOW 2 CVE-2026-6737

CVE-2026-6737_CVE-2026-6737

An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtai...

ASUS AsusPTPFilter CVE
LOW 3.3 CVE-2026-41498

Kimai: Team API Missing Object-Level Authorization_CVE-2026-41498

Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGra...

kimai kimai < 2.54.0 CVE
LOW 3.9 BA784FB7-16CB-

Exploit for Improper Certificate Validation in Bluestacks_BA784FB7-16CB-59E4-A360-285C35E3A1C9

CVE-2025-44964 — BlueStacks v5.20 Improper SSL Certificate Validation Severity: LOW CVSS 3.9 CWE: CWE-295 — Improper Certificate Validation Affecte...

N/A N/A GITHUBEXPLOIT
LOW 2.3 6A6412FB-9FCD-

Exploit for Improper Access Control in Oracle Vm_Virtualbox_6A6412FB-9FCD-53BB-BA01-3B1C5BBF56FE

CVE-2026-35250 my firstever cve is a 2.3 - Integer Overflow on DevVGAVBVA - can cause DoS from privileged guest - AI-assisted finding and PoC is co...

N/A N/A GITHUBEXPLOIT