Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-45289

CloudburstMC Protocol: Partially missing validation for FULL type authentication tokens_CVE-2026-45289

CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol ...

CloudburstMC Protocol < 3.0.0.Beta12-20260420.182526-15 CVE
MEDIUM 6.9 CVE-2026-41569

authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints_CVE-2026-41569

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter u...

goauthentik authentik < 2026.2.3 CVE
MEDIUM 5.3 CVE-2026-10624

SourceCodester Human Resource Management Employee View detailview.php resource injection_CVE-2026-10624

A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the f...

SourceCodester Human Resource Management 1.0 CVE
MEDIUM 6.9 CVE-2026-10620

code-projects Student Admission System index.php sql injection_CVE-2026-10620

A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of t...

code-projects Student Admission System 1.0 CVE
MEDIUM 6.9 CVE-2026-10619

sayan365 student-management-system improper authentication_CVE-2026-10619

A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function...

sayan365 student-management-system n/a CVE
MEDIUM 5.3 CVE-2026-35212

OpenCTI has XSS in the rendering of email-message observable body data_CVE-2026-35212

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to...

OpenCTI-Platform opencti < 7.260227.0 CVE
MEDIUM 5.3 CVE-2026-10661

ahujasid blender-mcp server.py open injection_CVE-2026-10661

A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file sr...

ahujasid blender-mcp 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b CVE
MEDIUM 6.9 CVE-2026-10650

warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption_CVE-2026-10650

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lw...

warmcat libwebsockets 4.5.0 CVE
MEDIUM 5.3 CVE-2026-9590

CVE-2026-9590_CVE-2026-9590

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry ...

Devolutions Server CVE
MEDIUM 5.4 CVE-2026-9522

CVE-2026-9522_CVE-2026-9522

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without admin...

Devolutions Server CVE