Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-44688

CVE-2026-44688_CVE-2026-44688

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without dis...

Eclipse Foundation Eclipse Theia CVE
HIGH 7.2 CVE-2025-52465

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page_CVE-2025-52465

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists...

geoserver org.geoserver.web:gs-web-app < 2.26.4 CVE
HIGH 7.2 CVE-2025-27511

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection_CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Exte...

geoserver org.geoserver.extension:gs-db2 < 2.27.0 CVE
HIGH 8.1 CVE-2026-56020

Webmin HTTP header authentication bypass_CVE-2026-56020

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a...

Webmin Webmin CVE
HIGH 8.8 CVE-2026-55237

AutoGPT SignUp Page has DOM-Based XSS and Open Redirect_CVE-2026-55237

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62...

Significant-Gravitas AutoGPT < 0.6.62 CVE
HIGH 7.8 CVE-2026-12505

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall_CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user informati...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.8 CVE-2026-12407

E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter_CVE-2026-12407

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. Th...

oleksandrz E2Pdf – Export Pdf Tool for WordPress CVE
HIGH 8.2 CVE-2026-48764

TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass_CVE-2026-48764

TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether th...

baptisteArno typebot.io < 3.17.2 CVE
HIGH 7.5 CVE-2026-50200

Steeltoe’s env sanitizer misses connection strings — leaks embedded DB passwords_CVE-2026-50200

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management...

SteeltoeOSS Steeltoe.Management.Endpoint < 4.2.0 CVE
HIGH 7.5 CVE-2026-50196

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch_CVE-2026-50196

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery....

SteeltoeOSS Steeltoe.Discovery.Eureka >= 4.0.0, < 4.2.0 CVE