Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-38061

CVE-2026-38061_CVE-2026-38061

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
CRITICAL 9.8 CVE-2026-38060

CVE-2026-38060_CVE-2026-38060

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
CRITICAL 9.1 CVE-2026-12316

Mitigation bypass in the DOM: Security component_CVE-2026-12316

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
CRITICAL 9.1 CVE-2026-12315

Mitigation bypass in the DOM: Security component_CVE-2026-12315

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird...

Mozilla Firefox 140.12 CVE
CRITICAL 9.1 CVE-2026-12304

Same-origin policy bypass in the Networking: Cookies component_CVE-2026-12304

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, a...

Mozilla Firefox 140.12 CVE
CRITICAL 9.3 CVE-2026-48777

FileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory_CVE-2026-48777

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Pat...

gtsteffaniak filebrowser < 1.3.3-stable CVE
CRITICAL 9.1 CVE-2026-22313

OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector_CVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vuln...

Radiflow iSAP Smart Collector 3.07-1 CVE
CRITICAL 9.8 CVE-2026-50890

CVE-2026-50890_CVE-2026-50890

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This v...

Bernd Bestel grocy v4.6.0 CVE
CRITICAL 9.1 CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read_CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argumen...

PEVANS Socket CVE
CRITICAL 9.1 CVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce_CVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of th...

BIAFRA Dancer2::Plugin::Auth::OAuth CVE