Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2025-9292

Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers_CVE-2025-9292

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances...

TP-Link Systems Inc. Omada Cloud Controller CVE
LOW 3.3 CVE-2026-20663

CVE-2026-20663_CVE-2026-20663

The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to ...

Apple iOS and iPadOS unspecified CVE
LOW 2 CVE-2025-55210

FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes_CVE-2025-55210

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API)...

FreePBX api >= 15.0.1alpha1, < 16.0.17 CVE
LOW 3.1 CVE-2026-20671

CVE-2026-20671_CVE-2026-20671

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequ...

Apple macOS unspecified CVE
LOW 1.3 CVE-2026-26031

Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students_CVE-2026-26031

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identifi...

frappe lms < 2.44.0 CVE
LOW 1.3 CVE-2026-0228

PAN-OS: Improper Validation of Terminal Server Agent Certificate_CVE-2026-0228

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certif...

Palo Alto Networks Cloud NGFW All CVE
LOW 3.6 CVE-2026-2345

Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers_CVE-2026-2345

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', .....

Proctorio Secure Exam Proctor Extension 1.5.25220.33 CVE
LOW 2.3 CVE-2025-12474

libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling_CVE-2025-12474

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the ...

Google libjxl 0.7 CVE
LOW 1.3 CVE-2026-22894

File Station 5_CVE-2026-22894

A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vul...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 1.3 CVE-2025-68406

Qsync Central_CVE-2025-68406

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vuln...

QNAP Systems Inc. Qsync Central 5.0.x.x CVE