Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-43663

CVE-2026-43663_CVE-2026-43663

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Proc...

Apple Safari CVE
MEDIUM 6.5 CVE-2026-39872

CVE-2026-39872_CVE-2026-39872

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Proc...

Apple Safari CVE
MEDIUM 6.5 CVE-2026-31016

CVE-2026-31016_CVE-2026-31016

Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the Iden...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-28979

CVE-2026-28979_CVE-2026-28979

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macO...

Apple Safari CVE
MEDIUM 6.5 CVE-2026-13593

CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away_CVE-2026-13593

CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory lea...

GTERMARS CSS::Minifier::XS CVE
MEDIUM 6.3 CVE-2026-57997

Strapi users-permissions – JWT Algorithm Confusion via Missing Algorithm Configuration_CVE-2026-57997

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowin...

strapi strapi CVE
MEDIUM 5.3 CVE-2026-10647

Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure_CVE-2026-10647

The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit c...

zephyrproject zephyr 4.1.0 CVE
MEDIUM 6.9 CVE-2026-53428

Unbounded memory allocation in highlight_lines range expansion in mdex_CVE-2026-53428

Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through...

leandrocp mdex 0.11.0 CVE
MEDIUM 6.2 CVE-2026-13757

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing_CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_va...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.1 CVE-2026-54889

Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)_CVE-2026-54889

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL s...

leandrocp mdex 0.8.3 CVE