Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-58174

Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Session Profile on Import_CVE-2026-58174

Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object withou...

nesquena hermes-webui CVE
MEDIUM 6.5 CVE-2026-58173

Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type_CVE-2026-58173

Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory ...

HKUDS Vibe-Trading CVE
MEDIUM 4.2 CVE-2026-58171

Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier_CVE-2026-58171

Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without vali...

HKUDS Vibe-Trading CVE
MEDIUM 6.5 CVE-2026-58167

Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privilege Users_CVE-2026-58167

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basi...

ccfos nightingale CVE
MEDIUM 6.5 CVE-2026-10655

Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it_CVE-2026-10655

The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descriptor directly from the calli...

zephyrproject zephyr 4.2.0 CVE
MEDIUM 6.4 CVE-2026-10653

Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref_CVE-2026-10653

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count...

zephyrproject zephyr 2.7.0 CVE
MEDIUM 4.8 CVE-2026-10652

Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)_CVE-2026-10652

Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR hea...

zephyrproject zephyr 4.3.0 CVE
MEDIUM 5.5 CVE-2026-43722

CVE-2026-43722_CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be ab...

Apple iOS and iPadOS CVE
MEDIUM 6.5 CVE-2026-55956

Apache Tomcat: Security constraints for default servlet ignored method_CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55955

Apache Tomcat: EncryptInterceptor not protected against replay attacks_CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE