Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-52783

OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others “storage..httpx_access_token” leads to Sensitive Data Exposure_CVE-2026-52783

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/Sh...

opf openproject < 17.3.3 CVE
HIGH 7.5 CVE-2026-47193

OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks_CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historica...

opf openproject < 17.3.3 CVE
HIGH 7.7 CVE-2026-55189

RustFS: FTP frontend skips IAM authorization on object reads_CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read ...

rustfs rustfs >= 1.0.0-alpha.1, <= 1.0.0-beta.8 CVE
HIGH 8.2 CVE-2026-55188

RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials_CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the ...

rustfs rustfs >= 1.0.0-alpha.1, <= 1.0.0-beta.8 CVE
HIGH 8.6 CVE-2026-49991

RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection_CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucke...

rustfs rustfs 1.0.0-beta.4 CVE
HIGH 8.7 CVE-2026-32833

Cudy LT300 3.0 OS Command Injection via NTP Configuration_CVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execu...

Shenzhen Cudy Technology Co., Ltd. LT300 3.0 CVE
HIGH 8.5 CVE-2026-54353

Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation_CVE-2026-54353

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist...

Budibase budibase < 3.39.9 CVE
HIGH 8.2 CVE-2026-54351

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override_CVE-2026-54351

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full ...

Budibase budibase < 3.39.9 CVE
HIGH 7.5 CVE-2026-52885

Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory_CVE-2026-52885

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the momen...

notepad-plus-plus notepad-plus-plus < 8.9.6.4 CVE
HIGH 7.8 CVE-2026-52884

Notepad++: CVE-2026-48800 Bypass_CVE-2026-52884

Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses...

notepad-plus-plus notepad-plus-plus = 8.9.6.1 CVE