Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-10619

sayan365 student-management-system improper authentication_CVE-2026-10619

A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function...

sayan365 student-management-system n/a CVE
MEDIUM 5.3 CVE-2026-35212

OpenCTI has XSS in the rendering of email-message observable body data_CVE-2026-35212

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to...

OpenCTI-Platform opencti < 7.260227.0 CVE
MEDIUM 5.3 CVE-2026-10661

ahujasid blender-mcp server.py open injection_CVE-2026-10661

A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file sr...

ahujasid blender-mcp 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b CVE
MEDIUM 6.9 CVE-2026-10650

warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption_CVE-2026-10650

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lw...

warmcat libwebsockets 4.5.0 CVE
MEDIUM 5.3 CVE-2026-9590

CVE-2026-9590_CVE-2026-9590

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry ...

Devolutions Server CVE
MEDIUM 5.4 CVE-2026-9522

CVE-2026-9522_CVE-2026-9522

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without admin...

Devolutions Server CVE
MEDIUM 5.3 CVE-2026-35443

NamelessMC: Forum reactions bypass the “view own topics only” restriction_CVE-2026-35443

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the...

NamelessMC Nameless = 2.2.4 CVE
MEDIUM 6.9 CVE-2026-8035

NULL pointer dereference in NI-PAL_CVE-2026-8035

Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due t...

NI NI-PAL CVE
MEDIUM 6.5 CVE-2026-5074

ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter_CVE-2026-5074

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX acti...

armember ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup CVE
MEDIUM 6.3 CVE-2026-49120

Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint_CVE-2026-49120

Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform un...

medplum medplum CVE