Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-12189

Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme_CVE-2026-12189

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a ...

Moovit Bus & Public Transit App 1.18 CVE
MEDIUM 5.3 CVE-2026-12188

Grit42 Grit GritEntityController grit_entity_controller.rb sql injection_CVE-2026-12188

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app...

Grit42 Grit 0.1 CVE
MEDIUM 4.8 CVE-2026-12190

Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme_CVE-2026-12190

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc....

Genspark AI Workspace App 2.8.4 CVE
MEDIUM 6.9 CVE-2026-54411

CVE-2026-54411_CVE-2026-54411

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in module...

Linux-PAM Linux-PAM CVE
MEDIUM 6.8 CVE-2026-54421

CVE-2026-54421_CVE-2026-54421

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unred...

OpenStack Ironic CVE
MEDIUM 5.3 1875515F-1163-

Exploit for Unchecked Input for Loop Condition in Isc Bind_1875515F-1163-510B-A697-82A204A481CB

CVE-2026-5950 - BIND 9 Resolver DoS Research notes and defensive guidance for CVE-2026-5950, an unbounded resend loop vulnerability in the BIND 9 r...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.1 CVE-2026-12175

CodeAstro Student Attendance Management System createStudents.php sql injection_CVE-2026-12175

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Adm...

CodeAstro Student Attendance Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-12176

SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting_CVE-2026-12176

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown ...

SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 CVE
MEDIUM 5.6 CVE-2026-6428

CVE-2026-6428_CVE-2026-6428

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x bef...

Koha Community Koha CVE
MEDIUM 4.3 CVE-2026-1291

Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation_CVE-2026-1291

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint...

tigroumeow Meow Gallery CVE