Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-33436

Stirling-PDF: Reflected XSS through crafted filename in file upload functionality_CVE-2026-33436

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoint...

Stirling-Tools Stirling-PDF < 2.0.0 CVE
LOW 1 CVE-2026-40319

Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check_CVE-2026-40319

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular exp...

Giskard-AI giskard-oss < 1.0.2b1 CVE
LOW 3.1 MS:CVE-2026-6312

Chromium: CVE-2026-6312 Insufficient policy enforcement in Passwords_MS:CVE-2026-6312

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 3.1 MS:CVE-2026-6313

Chromium: CVE-2026-6313 Insufficient policy enforcement in CORS_MS:CVE-2026-6313

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 2.7 CVE-2026-35496

CVE-2026-35496_CVE-2026-35496

A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level di...

CubeCart Limited CubeCart prior to 6.6.0 CVE
LOW 3.7 CVE-2026-40263

Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel_CVE-2026-40263

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only wh...

enchant97 note-mark < 0.19.2 CVE
LOW 1.7 CVE-2026-27820

zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption_CVE-2026-27820

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer o...

ruby zlib < 3.0.1 CVE
LOW 2.9 CVE-2026-41080

CVE-2026-41080_CVE-2026-41080

libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

libexpat project libexpat CVE
LOW 3.1 CVE-2026-3155

OneSignal – Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'_CVE-2026-3155

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is ...

onesignal OneSignal – Web Push Notifications CVE
LOW 2.9 CVE-2026-40947

CVE-2026-40947_CVE-2026-40947

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

Yubico libfido2 CVE