Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-54917

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access_CVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceb...

seaweedfs seaweedfs < 4.30 CVE
HIGH 7.1 CVE-2026-4930

DPA Countermeasures weakening on Series 3 devices_CVE-2026-4930

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryp...

silabs.com Simplicity SDK CVE
HIGH 7.1 CVE-2026-57520

Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint_CVE-2026-57520

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission t...

bitwarden server CVE
HIGH 8.2 CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation_CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pa...

wolfSSL wolfSSL 5.6.4 CVE
HIGH 8.3 CVE-2026-55958

Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage_CVE-2026-55958

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG...

wolfSSL wolfSSL 5.4.0 CVE
HIGH 8.7 CVE-2026-11310

X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring_CVE-2026-11310

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-ope...

wolfSSL wolfSSL 5.8.4 CVE
HIGH 7.5 CVE-2025-61027

CVE-2025-61027_CVE-2025-61027

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61023

CVE-2025-61023_CVE-2025-61023

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-9800

Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison_CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role...

Red Hat Red Hat Build of Keycloak CVE
HIGH 7.7 CVE-2026-9099

Keycloak: group-admin escalation to realm-admin_CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authentica...

Red Hat Red Hat Build of Keycloak CVE