Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3 CVE-2026-5379

runZero Platform MCP certification information leak_CVE-2026-5379

An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is a...

runZero Platform CVE
LOW 2.7 CVE-2026-4292

Privilege abuse in ModelAdmin.list_editable_CVE-2026-4292

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` inco...

djangoproject Django 6.0 CVE
LOW 2.1 CVE-2026-39349

OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure_CVE-2026-39349

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with ...

orangehrm orangehrm >= 5.0, < 5.8.1 CVE
LOW 2 CVE-2026-27949

Plane Exposes User Email (PII and part of credential) in GET Parameter_CVE-2026-27949

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's em...

makeplane plane < 1.3.0 CVE
LOW 2.8 CVE-2026-34781

Electron crashes in clipboard.readImage() on malformed clipboard image data_CVE-2026-34781

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0...

electron electron < 39.8.5 CVE
LOW 3.3 CVE-2026-28264

CVE-2026-28264_CVE-2026-28264

Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low...

Dell PowerProtect Agent CVE
LOW 2.3 CVE-2026-34720

Zammad has an origin validation error in SSO mechanism_CVE-2026-34720

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the hea...

zammad zammad < 6.5.4 CVE
LOW 2.1 CVE-2026-34248

Zammad has an information disclosure in ticket detail view of customers in shared organizations_CVE-2026-34248

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each othe...

zammad zammad >= 7.0.0, < 7.0.1 CVE
LOW 3.7 CVE-2026-34166

LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter_CVE-2026-34166

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly ac...

harttle liquidjs < 10.25.3 CVE
LOW 3.5 CVE-2026-35400

LORIS incorrectly trusts user input in publication module_CVE-2026-35400

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimagin...

aces Loris >= 20.0.0, < 27.0.3 CVE