Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-12706

Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()_CVE-2026-12706

A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed ...

Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 CVE
MEDIUM 5.6 CVE-2026-11941

Use-after-free in connection ID iterator and FFI functions_CVE-2026-11941

Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_n...

Cloudflare Quiche 0.20.0 CVE
CRITICAL 9.6 CVE-2026-56142

CVE-2026-56142_CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching a...

JetBrains Hub CVE
CRITICAL 9.8 CVE-2026-56141

CVE-2026-56141_CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable re...

JetBrains Hub CVE
HIGH 7.1 CVE-2026-53915

CVE-2026-53915_CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

JetBrains GoLand CVE
CRITICAL 10 CVE-2026-50242

CVE-2026-50242_CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct da...

JetBrains Hub CVE
CRITICAL 9.4 CVE-2026-44939

Command injection through unsanitized YAML parameter in Rancher_CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanit...

SUSE Rancher 2.14.0 CVE
LOW 3.7 CVE-2026-9143

Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen_CVE-2026-9143

There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently d...

NI grpc-device CVE
CRITICAL 9.1 CVE-2026-9142

Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present_CVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopb...

NI grpc-device CVE
HIGH 7.1 CVE-2026-4027

FlexNet Manager Suite Attachment File Disclosure_CVE-2026-4027

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due t...

Flexera FlexNet Manager Suite 2025 R1 CVE