Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-48851

CVE-2026-48851_CVE-2026-48851

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authen...

PuTTY PuTTY 0.77 CVE
LOW 3.7 CVE-2026-48850

CVE-2026-48850_CVE-2026-48850

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

PuTTY PuTTY 0.72 CVE
LOW 2.1 CVE-2026-47069

CRLF injection in cookie domain/path options in hackney_CVE-2026-47069

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:se...

benoitc hackney 0.9.0 CVE
LOW 2.3 CVE-2026-5222

Cargo can be coerced to share credentials between registries_CVE-2026-5222

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowe...

Rust Cargo 1.68.0 CVE
LOW 3.5 CVE-2026-48832

CVE-2026-48832_CVE-2026-48832

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

SPIP SPIP CVE
LOW 2.3 CVE-2026-9398

Besen BS20 EV Charging Station BLE/WiFi authentication replay_CVE-2026-9398

A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown part of the component BLE/WiFi...

Besen BS20 EV Charging Station 20260426 CVE
LOW 2.3 CVE-2026-9394

Besen BS20 EV Charging Station Bluetooth Low Energy weak password_CVE-2026-9394

A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low En...

Besen BS20 EV Charging Station 20260426 CVE
LOW 2.3 CVE-2026-9304

calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery_CVE-2026-9304

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app...

calcom cal.diy 4.9.0 CVE
LOW 3.1 CVE-2026-39967

TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter_CVE-2026-39967

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowi...

baptisteArno typebot.io < 3.16.0 CVE
LOW 3.1 CVE-2026-9249

CVE-2026-9249_CVE-2026-9249

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted pa...

Devolutions Server 2026.1.6.0 CVE