Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.8 CVE-2026-11931

Insecure Permissions on Authentication Token Cache File in Kiro IDE_CVE-2026-11931

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other loca...

AWS Kiro IDE CVE
MEDIUM 5.4 CVE-2026-8358

Heap buffer overflow in spreadsheet tracked-changes import_CVE-2026-8358

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change iden...

The Document Foundation LibreOffice 26.2 CVE
MEDIUM 5.4 CVE-2026-8357

Heap buffer overflow in Calc formula compilation_CVE-2026-8357

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of ma...

The Document Foundation LibreOffice 26.2 CVE
MEDIUM 5.4 CVE-2026-8356

Stack buffer overflow in PPT presentation import_CVE-2026-8356

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. T...

The Document Foundation LibreOffice 26.2 CVE
MEDIUM 5.4 CVE-2026-6047

Heap buffer overflow in OOXML text box element import_CVE-2026-6047

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box el...

The Document Foundation LibreOffice 25.8 CVE
MEDIUM 5.4 CVE-2026-6045

Heap buffer overflow in EMF+ gradient brush import_CVE-2026-6045

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The...

The Document Foundation LibreOffice 25.8 CVE
MEDIUM 5.4 CVE-2026-6040

Heap use-after-free in ODF number-format blank-width parsing_CVE-2026-6040

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not ch...

The Document Foundation LibreOffice 25.8 CVE
MEDIUM 5.4 CVE-2026-6039

Heap buffer overflow in DXF polyline import_CVE-2026-6039

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point cou...

The Document Foundation LibreOffice 25.8 CVE
MEDIUM 6.1 CVE-2026-49294

Valhalla has reflected XSS via unsanitized JSONP callback parameter_CVE-2026-49294

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to re...

valhalla valhalla <= 3.6.3 CVE
MEDIUM 6.5 CVE-2026-20262

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability_CVE-2026-20262

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a ...

Cisco Cisco Catalyst SD-WAN Manager 20.1.12 CVE