Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-31978

motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint_CVE-2026-31978

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ...

motioneye-project motioneye < 0.44.0 CVE
MEDIUM 6.5 CVE-2026-13208

Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body_CVE-2026-13208

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identit...

Red Hat Red Hat OpenShift Virtualization 4 CVE
MEDIUM 5.2 CVE-2026-13201

Kubevirt: virt-handler-rhel9: kubevirt: safepath openatnofollow symlink following via /proc/self/fd allows host file metadata modification_CVE-2026-13201

A flaw was found in KubeVirt's safepath package. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but...

Red Hat Red Hat OpenShift Virtualization 4 CVE
MEDIUM 5.5 CVE-2026-9775

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability_CVE-2026-9775

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary fil...

ATEN Unizon 2.7.262.002 CVE
MEDIUM 5.5 CVE-2026-9774

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability_CVE-2026-9774

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary...

ATEN Unizon 2.7.262.002 CVE
MEDIUM 5.3 CVE-2026-55455

Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist_CVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils...

appsmithorg appsmith < 2.1 CVE
MEDIUM 5.9 CVE-2026-54068

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon_CVE-2026-54068

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from au...

siyuan-note siyuan < 3.7.0 CVE
MEDIUM 6.1 CVE-2026-53766

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots_CVE-2026-53766

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpCont...

ChromeDevTools chrome-devtools-mcp >= 0.24.0, < 1.1.0 CVE
MEDIUM 6.1 CVE-2026-53765

chrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runtime directory_CVE-2026-53765

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chr...

ChromeDevTools chrome-devtools-mcp >= 0.20.0, < 1.1.0 CVE
MEDIUM 6.5 CVE-2026-10642

Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control_CVE-2026-10642

The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the...

zephyrproject zephyr 4.1.0 CVE