Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.7 CVE-2026-35069

CVE-2026-35069_CVE-2026-35069

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') v...

Dell PowerFlex CVE
MEDIUM 6 CVE-2026-20246

Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability_CVE-2026-20246

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an aff...

Cisco Cisco Umbrella Insights Virtual Appliance 2.6.0 CVE
MEDIUM 6.3 CVE-2026-20220

Cisco Crosswork Network Controller Remote Code Execution Vulnerability_CVE-2026-20220

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to e...

Cisco Cisco Crosswork Network Change Automation 3.0.0 CVE
MEDIUM 5.5 CVE-2026-1288

RFA File Parsing Vulnerability in Autodesk Revit_CVE-2026-1288

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulner...

Autodesk Revit 2027.0.0 CVE
MEDIUM 4.3 CVE-2026-12515

Katello: missing repository authorization in content_uploads exposes cross-product content existence_CVE-2026-12515

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsCon...

Red Hat Red Hat Hardened Images CVE
MEDIUM 4.3 CVE-2025-32748

CVE-2025-32748_CVE-2025-32748

Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could...

Dell PowerFlex rack CVE
MEDIUM 6 CVE-2026-55748

CVE-2026-55748_CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. ...

OpenStack Horizon 8.0.0 CVE
MEDIUM 4.8 CVE-2026-48142

NGINX ngx_http_charset_module vulnerability_CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location b...

F5 NGINX Open Source 1.13.10 CVE
MEDIUM 6.8 CVE-2026-48117

DroneAware’s Improper Account Activation in Registration and SSO Flows Leads to Account Takeover_CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack...

fduflyer DroneAware-Node-Releases < server-2026-05-20 CVE
MEDIUM 4.8 CVE-2026-40641

CVE-2026-40641_CVE-2026-40641

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attack...

Dell PowerFlex CVE