Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-50210

Weak Static Cryptographic Initialization Vectors_CVE-2026-50210

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plai...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 4.9 CVE-2026-50219

CVE-2026-50219_CVE-2026-50219

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset ...

libexpat project libexpat CVE
MEDIUM 6.7 CVE-2026-10805

Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend_CVE-2026-10805

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malfo...

Red Hat Multicluster Engine for Kubernetes CVE
MEDIUM 6.9 CVE-2026-49204

Hard-coded AWS Cognito Testing Accounts_CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.3 CVE-2026-49192

Summary Service Insecure Direct Object Reference_CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.8 CVE-2026-46447

CVE-2026-46447_CVE-2026-46447

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

OpenStack Ironic 17.0.0 CVE
MEDIUM 5.9 CVE-2026-48681

CVE-2026-48681_CVE-2026-48681

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

OpenStack Ironic 17.0.0 CVE
MEDIUM 4.9 CVE-2026-44917

CVE-2026-44917_CVE-2026-44917

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_temp...

OpenStack Ironic 17.0.0 CVE
MEDIUM 6.5 CVE-2026-8653

MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter_CVE-2026-8653

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and inc...

StylemixThemes MasterStudy LMS Pro CVE
MEDIUM 6.5 CVE-2026-41858

CVE-2026-41858_CVE-2026-41858

Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network a...

Cloud Foundry Foundation windows-utilities-release CVE