Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2025-60465

CVE-2025-60465_CVE-2025-60465

A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to caus...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-57914

Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures_CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to...

Apache Software Foundation Apache Kerby CVE
MEDIUM 4.3 CVE-2026-57925

CVE-2026-57925_CVE-2026-57925

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

JetBrains YouTrack CVE
MEDIUM 4.3 CVE-2026-57924

CVE-2026-57924_CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

JetBrains YouTrack CVE
MEDIUM 5.3 CVE-2026-57923

CVE-2026-57923_CVE-2026-57923

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

JetBrains YouTrack CVE
MEDIUM 4.3 CVE-2026-57921

CVE-2026-57921_CVE-2026-57921

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

JetBrains YouTrack CVE
MEDIUM 6.7 CVE-2026-53914

CVE-2026-53914_CVE-2026-53914

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

JetBrains Kotlin CVE
MEDIUM 5.4 CVE-2026-13426

Client4 fails to validate path parameters_CVE-2026-13426

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API r...

Mattermost github.com/mattermost/mattermost/server/public v0.0.0 CVE
MEDIUM 5.4 0D5ACD84-8796-

Exploit for Cross-site Scripting in Docmost_0D5ACD84-8796-5644-A05C-46FADC4B35D4

CVE-2026-34212 Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a ...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.4 0A738D4C-E642-

Exploit for Authorization Bypass Through User-Controlled Key in Docmost_0A738D4C-E642-58D3-988B-4E964946EC66

CVE-2026-34213 A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored ...

N/A N/A GITHUBEXPLOIT