Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509_CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused stri...

Go standard library crypto/x509 CVE
MEDIUM 5.3 CVE-2026-49077

WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability_CVE-2026-49077

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded ...

Tips and Tricks HQ WP eMember n/a CVE
MEDIUM 5.3 CVE-2026-10802

keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption_CVE-2026-10802

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/co...

keystonejs keystone 20260319 CVE
MEDIUM 4.3 CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. ._CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic...

HCL iControl 4.0.0 CVE
MEDIUM 6.1 CVE-2026-8916

CVE-2026-8916_CVE-2026-8916

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd...

Samsung Open Source rlottie dcfde72eae1b0464dc0dd760aec00ada6a148635 CVE
MEDIUM 6.9 CVE-2026-50226

Firmware Theft & IMEI Spoofing via Connect-OTA_CVE-2026-50226

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 6.9 CVE-2026-50224

Unauthenticated IPv6 WAN Management Exposure_CVE-2026-50224

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API ...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 6 CVE-2026-4881

CVE-2026-4881_CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level ...

Octopus Deploy Octopus Server 2023.0.0 CVE
MEDIUM 6.1 CVE-2026-49510

CVE-2026-49510_CVE-2026-49510

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023...

Samsung Open Source rlottie 21292665023e5074b38254432716866d00f1985f CVE
MEDIUM 6.1 CVE-2026-47320

CVE-2026-47320_CVE-2026-47320

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Seriali...

Samsung Open Source rlottie eae37633fda13ac05b25c6c95aacea4bc33c80a3 CVE