Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-47715

Bugsink: Issue event views can show an event from another project if its UUID is known_CVE-2026-47715

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affec...

bugsink bugsink < 2.2.0 CVE
LOW 3.8 CVE-2026-44410

Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE_CVE-2026-44410

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviati...

ZTE ZXUniPOS NDS-LTE V24.40.40 CVE
LOW 1.8 CVE-2025-71310

CVE-2025-71310_CVE-2025-71310

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious ...

BackdropCMS GDPR cookies module for Backdrop CMS CVE
LOW 3.7 CVE-2026-48847

CVE-2026-48847_CVE-2026-48847

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisonin...

Roundcube Webmail 1.6.0 CVE
LOW 3.7 CVE-2026-48852

CVE-2026-48852_CVE-2026-48852

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

PuTTY PuTTY 0.71 CVE
LOW 3.1 CVE-2026-48851

CVE-2026-48851_CVE-2026-48851

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authen...

PuTTY PuTTY 0.77 CVE
LOW 3.7 CVE-2026-48850

CVE-2026-48850_CVE-2026-48850

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

PuTTY PuTTY 0.72 CVE
LOW 2.1 CVE-2026-47069

CRLF injection in cookie domain/path options in hackney_CVE-2026-47069

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:se...

benoitc hackney 0.9.0 CVE
LOW 2.3 CVE-2026-5222

Cargo can be coerced to share credentials between registries_CVE-2026-5222

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowe...

Rust Cargo 1.68.0 CVE
LOW 3.5 CVE-2026-48832

CVE-2026-48832_CVE-2026-48832

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

SPIP SPIP CVE