Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.6 CVE-2026-38571

CVE-2026-38571_CVE-2026-38571

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART...

n/a n/a n/a CVE
MEDIUM 5.4 CVE-2026-50767

CVE-2026-50767_CVE-2026-50767

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System through 25.11 allows an au...

n/a n/a n/a CVE
MEDIUM 5.4 CVE-2026-50766

CVE-2026-50766_CVE-2026-50766

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System through 25.11 allows an authentica...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-50765

CVE-2026-50765_CVE-2026-50765

Cross-Site Scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System through 25.11 allows ...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2026-36908

CVE-2026-36908_CVE-2026-36908

A stack overflow in the AP4_Array::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service ...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2026-36907

CVE-2026-36907_CVE-2026-36907

A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service...

n/a n/a n/a CVE
MEDIUM 4.8 CVE-2026-9677

Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting_CVE-2026-9677

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it ...

Unknown Shariff for WordPress CVE
MEDIUM 6.5 CVE-2026-45259

sigqueue(2) missing capability mode restriction_CVE-2026-45259

sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not i...

FreeBSD FreeBSD 15.0-RELEASE CVE
MEDIUM 4.3 CVE-2026-9676

f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification_CVE-2026-9676

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing a...

Unknown F4 Post Tree CVE
MEDIUM 6.9 CVE-2026-41992

Global Buffer Overflow in GNU gzip_CVE-2026-41992

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between dif...

GNU gzip CVE