Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-1703

Limited path traversal when installing wheel archives_CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path trav...

Python Packaging Authority pip CVE
LOW 3.1 CVE-2026-1751

Missing Authorization in GitLab_CVE-2026-1751

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized ed...

GitLab GitLab 16.8 CVE
LOW 2.7 CVE-2025-13881

Org.keycloak.services.resources.admin: keycloak: limited administrator can retrieve sensitive user attributes via admin api_CVE-2025-13881

A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes ...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.7 CVE-2026-1518

Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in keycloak_CVE-2026-1518

A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.3 CVE-2026-1743

DJI Mavic Mini/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replay_CVE-2026-1743

A vulnerability has been found in DJI Mavic Mini, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of...

DJI Mavic Mini 01.00 CVE
LOW 2.4 CVE-2026-1735

Yealink MeetingBar A30 Diagnostic command injection_CVE-2026-1735

A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handle...

Yealink MeetingBar A30 133.321.0.3 CVE
LOW 3.2 A26C1C53-786D-

Exploit for CVE-2026-25211_A26C1C53-786D-5F34-A31D-BDF877F9DC09

Llama Stack pgvector Password Leak PoC CVE-2026-25211 Local Proof-of-Concept demonstrating plaintext database password exposure in initialization l...

N/A N/A GITHUBEXPLOIT
LOW 3.8 CVE-2025-15497

CVE-2025-15497_CVE-2025-15497

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a ...

OpenVPN OpenVPN 2.7_alpha1 CVE
LOW 2.7 CVE-2026-25050

Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy_CVE-2026-25050

Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerabl...

vendurehq vendure < 3.5.3 CVE
LOW 3.2 CVE-2026-25211

CVE-2026-25211_CVE-2026-25211

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

llamastack Llama Stack CVE