Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 1455C226-77CD-

Exploit for Improper Authentication in Google Android_1455C226-77CD-5803-A0CE-7D7BC815D6F6

BlueDucky Ver 2.1 Android 🦆 Thanks to all the people at HackNexus. Make sure you come join us on VC ! https://discord.gg/HackNexus NOTES: I will n...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.1 CVE-2026-48942

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 4.6 CVE-2026-9799

Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass_CVE-2026-9799

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource c...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 6.5 CVE-2026-9705

Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token_CVE-2026-9705

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), coul...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 4.9 CVE-2026-9083

Keycloak: keycloak: information disclosure through arbitrary filesystem path probing_CVE-2026-9083

A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesyst...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 5.5 CVE-2026-55439

Halo: Path Traversal in Backup Download Leads to Arbitrary File Read_CVE-2026-55439

Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated ...

halo-dev halo < 2.24.3 CVE
MEDIUM 6.8 CVE-2026-55411

ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization’s data-source secrets_CVE-2026-55411

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-...

ToolJet ToolJet < 3.20.1780-lts CVE
MEDIUM 5.3 CVE-2026-54573

Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy_CVE-2026-54573

Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl ...

outline outline < 1.8.0 CVE
MEDIUM 6.9 CVE-2026-54448

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser_CVE-2026-54448

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAl...

aquasecurity trivy < 0.71.0 CVE
MEDIUM 5.9 CVE-2026-54040

LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass_CVE-2026-54040

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/backup/regenerate endpoint r...

danny-avila LibreChat < 0.8.4-rc1 CVE