Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-47748

stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode parsing_CVE-2026-47748

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Ve...

leejet stable-diffusion.cpp < master-584-0a7ae07 CVE
MEDIUM 5.4 CVE-2026-46448

CVE-2026-46448_CVE-2026-46448

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

OpenStack Nova 18.0.0 CVE
MEDIUM 5.7 CVE-2026-12425

Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10_CVE-2026-12425

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center all...

PowerSchool Employee Access Center 23.10 CVE
MEDIUM 6.5 CVE-2026-53899

Cross-origin cookies could be leaked when opening a PDF link_CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookie...

Mozilla Firefox for iOS 152.0 CVE
MEDIUM 5.4 CVE-2026-12330

Incorrect boundary conditions in the Internationalization component_CVE-2026-12330

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Th...

Mozilla Firefox 115.37 CVE
MEDIUM 5.3 CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12_CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
MEDIUM 5.4 CVE-2026-12322

Clickjacking issue in the Widget: Gtk component_CVE-2026-12322

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.4 CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component_CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.3 CVE-2026-12320

Information disclosure in the Password Manager component_CVE-2026-12320

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.7 CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140....

Mozilla Firefox 140.12 CVE