Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-8494

Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title_CVE-2026-8494

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in a...

mbis Permalink Manager Lite CVE
MEDIUM 5.8 CVE-2026-55706

CVE-2026-55706_CVE-2026-55706

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

OpenBSD OpenBSD CVE
MEDIUM 6.8 CVE-2025-15642

Netskope Client Service Insufficient Access Controls_CVE-2025-15642

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to ...

Netskope Netskope Client CVE
MEDIUM 6.8 CVE-2025-15641

Netskope Client Exposed IOCTL with Insufficient Access Controls_CVE-2025-15641

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can...

Netskope Netskope Client CVE
MEDIUM 4.8 CVE-2026-48783

Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription_CVE-2026-48783

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and appli...

gitroomhq postiz-app < 2.21.8 CVE
MEDIUM 6.5 CVE-2026-47277

Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks_CVE-2026-47277

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-s...

runtipi runtipi >= 4.9.1, < 4.10.0 CVE
MEDIUM 6.5 CVE-2026-39433

WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability_CVE-2026-39433

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

mojoomla WPAMS n/a CVE
MEDIUM 5.6 CVE-2026-2604

Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling_CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus ac...

GNOME Evolution Data Server CVE
MEDIUM 6.5 CVE-2025-69137

WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability_CVE-2025-69137

Subscriber Broken Access Control in Genemy

Jthemes Genemy n/a CVE
MEDIUM 6.8 CVE-2026-48782

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)_CVE-2026-48782

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, an...

pydantic pydantic-ai >= 1.56.0, < 1.102.0 CVE