Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-57280

CVE-2026-57280_CVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each ...

Jenkins Project Jenkins Script Security Plugin CVE
MEDIUM 4.6 CVE-2026-50699

Frappe Framework 17.0.0-dev – Stored XSS in Auto Repeat dashboard schedule rendering_CVE-2026-50699

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Aut...

Frappe Frappe Framework 17.0.0-dev CVE
MEDIUM 4.6 CVE-2026-50698

Frappe Framework 17.0.0-dev – Stored XSS in Audit Trail template rendering_CVE-2026-50698

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled i...

Frappe Frappe Framework 17.0.0-dev CVE
HIGH 7.3 CVE-2026-12986

CVE-2026-12986_CVE-2026-12986

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attac...

Payara Payara Server 7.2025.1 CVE
HIGH 8.2 CVE-2026-11878

Reflected Cross-Site Scripting vulnerability in OpenText Access Manager_CVE-2026-11878

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scr...

OpenText Access Manager 5.1 CVE
MEDIUM 6.3 CVE-2026-11877

Missing Authorization Vulnerability in OpenText Access Manager_CVE-2026-11877

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before ...

OpenText Access Manager 5.1 CVE
CRITICAL 9.3 CVE-2026-56121

Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization_CVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code e...

feast-dev feast CVE
HIGH 8.3 CVE-2026-56111

Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler_CVE-2026-56111

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability ...

MarlinFirmware Marlin CVE
HIGH 7.7 CVE-2026-55488

motionEye’s Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read_CVE-2026-55488

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versi...

motioneye-project motioneye < 0.44.0 CVE
MEDIUM 4.8 CVE-2026-50712

Frappe Framework 17.0.0-dev – Stored XSS in Tree View node label rendering_CVE-2026-50712

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled i...

Frappe Frappe Framework 17.0.0-dev CVE