Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-4027

FlexNet Manager Suite Attachment File Disclosure_CVE-2026-4027

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due t...

Flexera FlexNet Manager Suite 2025 R1 CVE
HIGH 8.7 CVE-2026-4026

FlexNet Manager Suite Privilege Escalation Vulnerability_CVE-2026-4026

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to accou...

Flexera FlexNet Manager Suite 2025 R1 CVE
HIGH 8.8 CVE-2026-49357

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication_CVE-2026-49357

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop app...

dtwang line-desktop-mcp < 1.1.2 CVE
HIGH 7.5 CVE-2026-48139

NULL pointer dereference vulnerability in NI grpc-device data moniker service_CVE-2026-48139

There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of ser...

NI grpc-device CVE
HIGH 7.5 CVE-2026-48138

Out-of-bounds read vulnerability in the NI grpc-device streaming API_CVE-2026-48138

There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of servi...

NI grpc-device CVE
HIGH 7 CVE-2026-39999

Apache APISIX: JWT Algorithm Confusion allows authentication bypass_CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain config...

Apache Software Foundation Apache APISIX 2.2 CVE
HIGH 8.6 CVE-2026-12104

Authenticated OS Command Injection in Bondix_CVE-2026-12104

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an auth...

SIMA GmbH Bondix Server CVE
HIGH 8.5 CVE-2025-71326

AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation_CVE-2025-71326

AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute c...

Avast AVAST Antivirus 25.11 CVE
HIGH 8.8 MALWAREBYTES:43...

Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap_MALWAREBYTES:430DE23FF1022B331371E640A7316DE9

Apple has patched a Bluetooth flaw in Beats Studio Buds that could potentially turn your earbuds into a nearby wiretap. When you buy a pair of Blu...

N/A N/A MALWAREBYTES
HIGH 8.1 CVE-2026-12292

Incorrect boundary conditions in the Web Audio component_CVE-2026-12292

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thu...

Mozilla Firefox 140.12 CVE