Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-10771

crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery_CVE-2026-10771

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zb...

crmeb crmeb_java 1.4 CVE
MEDIUM 6.9 CVE-2026-10777

ealpha072 Student-Management-System Administrative Backend config.php improper authentication_CVE-2026-10777

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is som...

ealpha072 Student-Management-System 01451bd7a2f58cdda07bd0b86e3967582e3ecd08 CVE
MEDIUM 4.3 CVE-2026-36618

CVE-2026-36618_CVE-2026-36618

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-36604

CVE-2026-36604_CVE-2026-36604

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external...

n/a n/a n/a CVE
MEDIUM 4.8 CVE-2026-43924

FOSSBilling has an open redirect via administrator-configured redirect targets_CVE-2026-43924

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL sche...

FOSSBilling FOSSBilling < 0.8.0 CVE
MEDIUM 6.9 CVE-2026-40495

FOSSBilling version exposed via asset cache buster_CVE-2026-40495

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache ...

FOSSBilling FOSSBilling < 0.8.0 CVE
MEDIUM 6.5 243CDB42-BE28-

Exploit for CVE-2026-2256_243CDB42-BE28-5810-BB45-078630950EB9

CVE-2026-2256-Threat-Model----ms-agent-Command-Injection...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-42507

Arbitrary inputs are included in errors without any escaping in net/textproto_CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject ...

Go standard library net/textproto CVE
MEDIUM 6.5 CVE-2026-35718

CVE-2026-35718_CVE-2026-35718

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers t...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-33553

CVE-2026-33553_CVE-2026-33553

Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

n/a n/a n/a CVE