Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-47220

Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format_CVE-2026-47220

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SER...

envoyproxy envoy >= 1.38.0, < 1.38.3 CVE
HIGH 7.6 PACKETSTORM:224380

📄 TypeBot Server-Side Request Forgery_PACKETSTORM:224380

TypeBot versions prior to 3.16.0 suffer from a server-side request forgery vulnerability...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:224376

📄 Yeoman Environment 6.0.0 Code Execution_PACKETSTORM:224376

Yeoman Environment versions 2.9.0 through 6.0.0 have an issue where missing generators can be installed without user confirmation, turning attacker...

N/A N/A PACKETSTORM
HIGH 8.3 PACKETSTORM:224372

📄 Plane Improper Authorization_PACKETSTORM:224372

Plane's asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user rea...

N/A N/A PACKETSTORM
HIGH 7.5 CVE-2026-46602

Lack of limit on tile sizes in x/image/tiff in golang.org/x/image_CVE-2026-46602

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to...

golang.org/x/image golang.org/x/image/tiff CVE
HIGH 7.5 CVE-2026-46601

Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image_CVE-2026-46601

The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.

golang.org/x/image golang.org/x/image/webp CVE
HIGH 7.7 CVE-2026-37149

CVE-2026-37149_CVE-2026-37149

GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37454

CVE-2026-37454_CVE-2026-37454

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DE...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37453

CVE-2026-37453_CVE-2026-37453

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38637

CVE-2026-38637_CVE-2026-38637

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted ...

n/a n/a n/a CVE