Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-10661

ahujasid blender-mcp server.py open injection_CVE-2026-10661

A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file sr...

ahujasid blender-mcp 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b CVE
MEDIUM 6.9 CVE-2026-10650

warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption_CVE-2026-10650

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lw...

warmcat libwebsockets 4.5.0 CVE
MEDIUM 5.3 CVE-2026-9590

CVE-2026-9590_CVE-2026-9590

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry ...

Devolutions Server CVE
MEDIUM 5.4 CVE-2026-9522

CVE-2026-9522_CVE-2026-9522

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without admin...

Devolutions Server CVE
MEDIUM 5.3 CVE-2026-35443

NamelessMC: Forum reactions bypass the “view own topics only” restriction_CVE-2026-35443

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the...

NamelessMC Nameless = 2.2.4 CVE
MEDIUM 6.9 CVE-2026-8035

NULL pointer dereference in NI-PAL_CVE-2026-8035

Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due t...

NI NI-PAL CVE
MEDIUM 6.5 CVE-2026-5074

ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter_CVE-2026-5074

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX acti...

armember ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup CVE
MEDIUM 6.3 CVE-2026-49120

Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint_CVE-2026-49120

Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform un...

medplum medplum CVE
MEDIUM 6.6 CVE-2026-47265

AIOHTTP vulnerable to cross-origin redirect with per-request cookies_CVE-2026-47265

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter o...

aio-libs aiohttp < 3.14.0 CVE
MEDIUM 6.9 CVE-2026-41577

authentik: SAML source does not validate Conditions, timing, or audience on assertions_CVE-2026-41577

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.pars...

goauthentik authentik < 2025.12.5 CVE