Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2026-20684

CVE-2026-20684_CVE-2026-20684

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.

Apple macOS CVE
LOW 3.3 CVE-2026-4761

Unnecessary permissions on private keys of certificates installed by Network and Security Wizard_CVE-2026-4761

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the...

CODRA Panorama Suite Panorama Suite 2025 CVE
LOW 3.7 CVE-2026-4363

Incorrect Authorization in GitLab_CVE-2026-4363

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under...

GitLab GitLab 18.1 CVE
LOW 3.1 CVE-2025-14808

IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information_CVE-2025-14808

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTT...

IBM InfoSphere Information Server 11.7.0.0 CVE
LOW 2 CVE-2026-4823

Enter Software Iperius Backup NTLM2 information disclosure_CVE-2026-4823

A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTL...

Enter Software Iperius Backup 8.7.0 CVE
LOW 3.1 CVE-2026-4874

Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation_CVE-2026-4874

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` pa...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.6 CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability_CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.1 CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability_CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.7 CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability_CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or imp...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 2.6 CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability_CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user info...

HCL Aftermarket DPC version 1.0.0 CVE