Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-49342

YARD static cache reads raw traversal paths before router sanitization_CVE-2026-49342

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path...

lsegal yard < 0.9.44 CVE
MEDIUM 4.3 CVE-2026-49337

libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`_CVE-2026-49337

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_...

strukturag libde265 < 1.0.20 CVE
MEDIUM 6.5 CVE-2026-48129

Kestra task inputFiles accepts traversal filenames for worker file writes_CVE-2026-48129

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` write...

kestra-io kestra < 1.0.43 CVE
MEDIUM 6.5 CVE-2026-50519

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability_CVE-2026-50519

{“lastseen”:””,”description”:””,”published”:”2026-06-19T20:28:35.395Z”,&#82...

Microsoft GitHub Copilot Chat 1.0.0 CVE
MEDIUM 6.5 CVE-2026-42895

Microsoft Copilot Tampering Vulnerability_CVE-2026-42895

{“lastseen”:””,”description”:””,”published”:”2026-06-19T20:27:46.785Z”,&#82...

Microsoft Microsoft 365 Copilot - CVE
MEDIUM 6.5 CVE-2026-49359

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option_CVE-2026-49359

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the...

pontedilana php-weasyprint < 2.6.0 CVE
MEDIUM 6.5 CVE-2026-49271

libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder_CVE-2026-49271

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compress...

strukturag libheif < 1.22.1 CVE
MEDIUM 5.5 CVE-2026-49336

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter_CVE-2026-49336

@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-previe...

microsoft kiota-typescript >= 1.0.0-preview.97, < 1.0.0-preview.102 CVE
MEDIUM 4.3 CVE-2026-49288

Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources_CVE-2026-49288

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view ...

statamic cms < 5.73.23 CVE
MEDIUM 5.3 CVE-2026-12238

WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation_CVE-2026-12238

The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. ...

wpgmaps WP Go Maps – Google Map, OpenStreetMap, Leaflet Map CVE