Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2026-55583

Twenty: Cross-workspace IDOR in AgentTurnResolver_CVE-2026-55583

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direc...

twentyhq twenty < 2.9.0 CVE
HIGH 8.6 CVE-2026-47389

Mastodon: SSRF protection bypass on older Ruby versions_CVE-2026-47389

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older tha...

mastodon mastodon >= 4.5.0-beta.1, < 4.5.10 CVE
HIGH 8.7 CVE-2026-46348

Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)_CVE-2026-46348

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ...

mastodon mastodon >= 4.5.0-beta.1, < 4.5.10 CVE
HIGH 7.1 CVE-2026-27708

FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access_CVE-2026-27708

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ...

FOSSBilling FOSSBilling < 0.8.0 CVE
HIGH 8 CVE-2026-23879

py7zr: Arbitrary File Write Vulnerability_CVE-2026-23879

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below...

miurahr py7zr < 1.1.3 CVE
HIGH 8.8 CVE-2026-0126

CVE-2026-0126_CVE-2026-0126

In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional exe...

Google Android Android kernel CVE
HIGH 8.6 CVE-2026-49269

CVE-2026-49269_CVE-2026-49269

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU re...

Apple Apple M1 GPU Legacy CVE
HIGH 8.2 CVE-2026-54904

concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`_CVE-2026-54904

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop wh...

ruby-concurrency concurrent-ruby < 1.3.7 CVE
HIGH 7.5 CVE-2026-54297

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters_CVE-2026-54297

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Farada...

lostisland faraday >= 1.0.0, < 1.10.6 CVE
HIGH 8.8 CVE-2026-13164

Unauthenticated self-registration in MailerUp allows access to stored email data_CVE-2026-13164

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp

Mailerup Mailerup CVE