Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.8 CVE-2025-15642

Netskope Client Service Insufficient Access Controls_CVE-2025-15642

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to ...

Netskope Netskope Client CVE
MEDIUM 6.8 CVE-2025-15641

Netskope Client Exposed IOCTL with Insufficient Access Controls_CVE-2025-15641

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can...

Netskope Netskope Client CVE
MEDIUM 4.8 CVE-2026-48783

Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription_CVE-2026-48783

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and appli...

gitroomhq postiz-app < 2.21.8 CVE
MEDIUM 6.5 CVE-2026-47277

Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks_CVE-2026-47277

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-s...

runtipi runtipi >= 4.9.1, < 4.10.0 CVE
MEDIUM 6.5 CVE-2026-39433

WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability_CVE-2026-39433

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

mojoomla WPAMS n/a CVE
MEDIUM 5.6 CVE-2026-2604

Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling_CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus ac...

GNOME Evolution Data Server CVE
MEDIUM 6.5 CVE-2025-69137

WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability_CVE-2025-69137

Subscriber Broken Access Control in Genemy

Jthemes Genemy n/a CVE
MEDIUM 6.8 CVE-2026-48782

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)_CVE-2026-48782

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, an...

pydantic pydantic-ai >= 1.56.0, < 1.102.0 CVE
MEDIUM 4.7 CVE-2026-44587

CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters_CVE-2026-44587

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to e...

carrierwaveuploader carrierwave < 2.2.7 CVE
MEDIUM 5.7 CVE-2026-0165

CVE-2026-0165_CVE-2026-0165

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote in...

Google Android Android kernel CVE