Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12003

CPython >3.11 Insecure Input Validation resulting in privilege escalation_CVE-2026-12003

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and ...

Python Software Foundation CPython CVE
MEDIUM 6.5 PACKETSTORM:223516

📄 Apache Flink Kubernetes Operator 1.14.0 Server-Side Request Forgery_PACKETSTORM:223516

This is a Metasploit auxiliary module to demonstrate a service-side request forgery vulnerability in Apache Flink Kubernetes Operator version 1.14....

N/A N/A PACKETSTORM
MEDIUM 6.8 CVE-2026-36933

CVE-2026-36933_CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2025-70102

CVE-2025-70102_CVE-2025-70102

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-53900

Cookie injection was possible when opening a PDF link_CVE-2026-53900

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site...

Mozilla Firefox for iOS 152.0 CVE
MEDIUM 6.5 CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component_CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
MEDIUM 5.4 CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component_CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 6.5 CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component_CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 4.7 CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 1...

Mozilla Firefox 140.12 CVE
MEDIUM 4.3 CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component_CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE