Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-11442

Allegra exportReport Directory Traversal Information Disclosure Vulnerability_CVE-2026-11442

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inf...

Allegra Allegra 8.1.10.5 CVE
MEDIUM 5.5 CVE-2025-46313

CVE-2025-46313_CVE-2025-46313

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Apple macOS CVE
MEDIUM 5.5 CVE-2025-43278

CVE-2025-43278_CVE-2025-43278

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-24165

CVE-2025-24165_CVE-2025-24165

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7....

Apple macOS CVE
MEDIUM 5 CVE-2026-54055

Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol_CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transm...

kovidgoyal kitty < 0.47.2 CVE
MEDIUM 6.1 CVE-2026-54397

MISP event editing allows unauthorized assignment to undisclosed sharing groups_CVE-2026-54397

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form da...

misp misp CVE
MEDIUM 5.3 CVE-2026-54396

MISP AuthKey edit endpoint allows authenticated user email enumeration_CVE-2026-54396

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit reques...

misp misp CVE
MEDIUM 5.3 CVE-2026-54395

MISP UiBeta event index reflected XSS in advanced filter popup_CVE-2026-54395

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScr...

misp misp CVE
MEDIUM 5.3 CVE-2026-54394

MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG files_CVE-2026-54394

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using ...

misp misp CVE
MEDIUM 5.1 CVE-2026-54393

MISP Overmind theme stored XSS via unvalidated homepage setting_CVE-2026-54393

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-cont...

misp misp CVE