Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2026-37462

CVE-2026-37462_CVE-2026-37462

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) vi...

n/a n/a n/a CVE
CRITICAL 9 CVE-2026-36748

CVE-2026-36748_CVE-2026-36748

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Rock RMS RockRMS v16.13, before v17.7.0 CVE
CRITICAL 9.8 CVE-2026-36576

CVE-2026-36576_CVE-2026-36576

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute a...

openlabs docker-wkhtmltopdf-aas up to commit 9f50579 CVE
HIGH 7.8 CVE-2026-40290

OP-TEE has a Use-After-Free race in FF-A shared-memory teardown_CVE-2026-40290

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os >= 3.16.0, < 4.11.0 CVE
MEDIUM 6.3 CVE-2026-39107

CVE-2026-39107_CVE-2026-39107

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or en...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-36615

CVE-2026-36615_CVE-2026-36615

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents t...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-36613

CVE-2026-36613_CVE-2026-36613

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST reque...

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-36608

CVE-2026-36608_CVE-2026-36608

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin inte...

Mercusys Mercusys AC12G AC12G(EU)_V1_200909 CVE
HIGH 8.8 CVE-2026-36607

CVE-2026-36607_CVE-2026-36607

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (c...

Mercusys Mercusys AC12G AC12G(EU)_V1_200909 CVE
HIGH 7.1 CVE-2026-36606

CVE-2026-36606_CVE-2026-36606

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mod...

n/a n/a n/a CVE