Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.6 CVE-2026-48480

netty-incubator-codec-ohttp OHttpVersionChunkDraft’s Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation_CVE-2026-48480

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-...

netty netty-incubator-codec-ohttp < 0.0.22.Final CVE
MEDIUM 5.3 CVE-2026-40898

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion_CVE-2026-40898

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HT...

quic-go quic-go < 0.59.1 CVE
MEDIUM 6.5 CVE-2026-36499

CVE-2026-36499_CVE-2026-36499

A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an ex...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2025-65640

CVE-2025-65640_CVE-2025-65640

Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper san...

n/a n/a n/a CVE
MEDIUM 4.6 CVE-2026-36178

CVE-2026-36178_CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly ...

n/a n/a n/a CVE
MEDIUM 6.8 CVE-2026-36175

CVE-2026-36175_CVE-2026-36175

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interr...

n/a n/a n/a CVE
MEDIUM 6.9 CVE-2026-7774

tarfile.data_filter path traversal bypass allows writing outside the extraction directory_CVE-2026-7774

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive ...

Python Software Foundation CPython CVE
MEDIUM 5.3 CVE-2026-41178

OpenTelemetry-Go’s baggage parsing no longer caps raw header length_CVE-2026-41178

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to proces...

open-telemetry go.opentelemetry.io/otel/baggage = 1.41.0 CVE
MEDIUM 5.4 CVE-2026-40930

LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body_CVE-2026-40930

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inte...

pnggroup libpng = 1.8.0 CVE
MEDIUM 5.3 CVE-2026-10815

LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization_CVE-2026-10815

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknow...

LakshayD02 Hostel-Management-System-PHP f87e67c283bab6f718faf2fec6ae39a13bd7036b CVE