Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-39388

OpenBao’s Certificate Authentication Allows Token Renewal With Different Certificate_CVE-2026-39388

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a tok...

openbao openbao < 2.5.3 CVE
LOW 2 CVE-2026-41330

OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy_CVE-2026-41330

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Do...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-22051

CVE-2026-22051_CVE-2026-22051

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Suc...

NETAPP StorageGRID (formerly StorageGRID Webscale) CVE
LOW 2.3 CVE-2026-0930

Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize_CVE-2026-0930

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of...

wolfSSL wolfSSH 1.4.15 CVE
LOW 3.7 CVE-2026-32690

Apache Airflow: 3.x – Nested Variable Secret Values Bypass Redaction via max_depth=1_CVE-2026-32690

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored a...

Apache Software Foundation Apache Airflow 3.0.0 CVE
LOW 2.1 CVE-2026-5958

Race Condition in GNU Sed_CVE-2026-5958

When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem ...

GNU Sed 4.1e CVE
LOW 2.3 CVE-2026-6611

liangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key_CVE-2026-6611

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the comp...

liangliangyy DjangoBlog 2.1.0 CVE
LOW 3.5 CVE-2026-40334

libgphoto2 missing null termination in ptp_unpack_Canon_FE() filename buffer in ptp-pack.c_CVE-2026-40334

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE(...

gphoto libgphoto2 <= 2.5.33 CVE
LOW 2.4 CVE-2026-40336

libgphoto2 has memory leak in ptp_unpack_Sony_DPD() secondary enumeration list in ptp-pack.c_CVE-2026-40336

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/pt...

gphoto libgphoto2 <= 2.5.33 CVE
LOW 3.5 CVE-2026-40341

libgphoto2 has an OOB Read in ptp_unpack_EOS_FocusInfoEx_CVE-2026-40341

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could...

gphoto libgphoto2 <= 2.5.33 CVE