Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-3196

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation_CVE-2026-3196

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bou...

N/A N/A 8.2.0 CVE
MEDIUM 6.9 CVE-2026-55205

Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint_CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that all...

nesquena hermes-webui CVE
MEDIUM 4.7 CVE-2026-54106

U.S. GAO EPDS and CBCA EDS network access control bypass_CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE
MEDIUM 6.9 CVE-2026-54105

U.S. GAO EPDS and CBCA EDS user information disclosure_CVE-2026-54105

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE
MEDIUM 5.1 CVE-2026-11982

Stored XSS via missing XSS safety check in Admin2 Pages API partial validation_CVE-2026-11982

Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.

Grav grav-plugin-api 1.7.52 CVE
MEDIUM 4.7 CVE-2026-48986

pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication_CVE-2026-48986

pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an in...

mcdope pam_usb < 0.9.2 CVE
MEDIUM 5.5 CVE-2026-48985

pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field_CVE-2026-48985

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_loginctl_local() can cause ...

mcdope pam_usb < 0.9.2 CVE
MEDIUM 4.7 CVE-2026-48984

pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap_CVE-2026-48984

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfree() memory release helper i...

mcdope pam_usb < 0.9.2 CVE
MEDIUM 5.3 CVE-2026-9692

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely_CVE-2026-9692

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 h...

HAYAJO Mojolicious::Sessions::Storable CVE
MEDIUM 6.7 CVE-2026-55392

NILFS utilities – Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size_CVE-2026-55392

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock ...

nilfs-dev nilfs-utils CVE