Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-47138

Parse Server: Pre-authentication denial of service via client version header regex backtracking_CVE-2026-47138

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1,...

parse-community parse-server < 8.6.77 CVE
HIGH 8.7 CVE-2026-42947

Naxclow IoT Platform Authorization bypass through User-Controlled key_CVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an ar...

Naxclow Smart Doorbell X3 All CVE
MEDIUM 6.9 CVE-2026-42932

Naxclow IoT Platform Generation of Predictable Numbers or Identifiers_CVE-2026-42932

Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identif...

Naxclow Smart Doorbell X3 All CVE
HIGH 7.2 CVE-2026-42306

Moby: Race condition in docker cp allows bind mount redirection to host path_CVE-2026-42306

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prio...

moby moby github.com/docker/docker/daemon <= 28.5.2 CVE
MEDIUM 6.1 CVE-2026-41568

Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap_CVE-2026-41568

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prio...

moby moby github.com/docker/docker/daemon <= 28.5.2 CVE
CRITICAL 9.2 CVE-2026-28742

Naxclow IoT Platform Use of hard-coded cryptographic key_CVE-2026-28742

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is ...

Naxclow Smart Doorbell X3 All CVE
HIGH 8.7 CVE-2026-12143

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)_CVE-2026-12143

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and ...

form-data form-data CVE
HIGH 8.8 CVE-2026-12043

Heap double-free in AWS Common Runtime aws-c-http_CVE-2026-12043

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a se...

AWS aws-c-http 0.4.22 CVE
MEDIUM 5.1 CVE-2026-10715

Camaleon CMS 2.9.2 – Improper authorization in draft autosave endpoint_CVE-2026-10715

Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated us...

Camaleon CMS Camaleon CMS 2.9.2 CVE
MEDIUM 5.1 CVE-2026-54357

MISP improper authorization allows organization administrators to modify site administrator user settings_CVE-2026-54357

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to ...

misp misp CVE