Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-48618

CVE-2026-48618_CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due t...

nodejs node 22.22.3 CVE
HIGH 8.8 921E88F8-3925-

Exploit for CVE-2026-43503_921E88F8-3925-519D-9067-4928D48E9B4D

CVE-2026-43503 — DirtyClone Linux local privilege escalation. A cloned skbuff loses the SKBFLSHAREDFRAG flag, so ESP in-place decryption writes int...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2026-40941

Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages_CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass all...

Cacti cacti < 1.2.31 CVE
HIGH 7.2 CVE-2026-40083

Cacti: SQL Injection in managers.php_CVE-2026-40083

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+im...

Cacti cacti < 1.2.31 CVE
HIGH 8.7 CVE-2026-9221

Setracker2 Children’s Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm_CVE-2026-9221

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating ...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker CVE
HIGH 8.7 CVE-2026-9220

Setracker2 Children’s Smartwatch Ecosystem Use of hard-coded cryptographic key_CVE-2026-9220

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hard...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 3.1.5 CVE
HIGH 8.3 CVE-2026-9219

Setracker2 Children’s Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers_CVE-2026-9219

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker CVE
HIGH 8.8 CVE-2026-6679

DTLS 1.3 ACK serialization heap buffer overflow via integer truncation_CVE-2026-6679

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due ...

wolfSSL wolfSSL 5.4.0 CVE
HIGH 8.8 CVE-2026-56445

pydicom pynetdicom Library Path Traversal_CVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizat...

pydicom pynetdicom Library 1.0.0 CVE
HIGH 8.3 CVE-2026-12473

OHIF Viewers DICOM Server-Side request forgery_CVE-2026-12473

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global a...

Open Health Imaging Foundation (OHIF) DICOM Web Viewer Framework CVE