Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-39967

TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter_CVE-2026-39967

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowi...

baptisteArno typebot.io < 3.16.0 CVE
LOW 3.1 CVE-2026-9249

CVE-2026-9249_CVE-2026-9249

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted pa...

Devolutions Server 2026.1.6.0 CVE
LOW 2.6 CVE-2026-9248

CVE-2026-9248_CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy doc...

Devolutions Server 2026.1.6.0 CVE
LOW 2.4 CVE-2026-9247

CVE-2026-9247_CVE-2026-9247

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entr...

Devolutions Server 2026.1.6.0 CVE
LOW 2.7 CVE-2026-8477

CVE-2026-8477_CVE-2026-8477

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user ...

Devolutions Server 2026.1.6.0 CVE
LOW 2.1 CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme_CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript tha...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2.3 CVE-2026-8347

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog_CVE-2026-8347

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-ent...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.3 CVE-2026-8340

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion_CVE-2026-8340

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publi...

Concrete CMS Concrete CMS 5.0 CVE
LOW 3.6 CVE-2025-46371

CVE-2025-46371_CVE-2025-46371

Dell PowerFlex Manager, version(s)

Dell PowerFlex Manager (Appliance) CVE
LOW 2.3 CVE-2026-25608

Lack of traffic encryption in STER_CVE-2026-25608

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensiti...

Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy STER CVE