Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-10701

Incorrect boundary conditions in the Graphics: Text component_CVE-2026-10701

Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.

Mozilla Firefox 151.0.3 CVE
HIGH 7.4 CVE-2025-64390

CVE-2025-64390_CVE-2025-64390

A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be esc...

Sony PS4 13.00 CVE
HIGH 7.5 CVE-2026-9516

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws_CVE-2026-9516

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip ...

RURBAN Cpanel::JSON::XS CVE
HIGH 7.3 CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled_CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() col...

RURBAN Cpanel::JSON::XS CVE
MEDIUM 6.5 CVE-2025-70101

CVE-2025-70101_CVE-2025-70101

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-70100

CVE-2025-70100_CVE-2025-70100

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause ...

n/a n/a n/a CVE
MEDIUM 5 CVE-2025-60477

CVE-2025-60477_CVE-2025-60477

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-37462

CVE-2026-37462_CVE-2026-37462

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) vi...

n/a n/a n/a CVE
CRITICAL 9 CVE-2026-36748

CVE-2026-36748_CVE-2026-36748

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Rock RMS RockRMS v16.13, before v17.7.0 CVE
CRITICAL 9.8 CVE-2026-36576

CVE-2026-36576_CVE-2026-36576

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute a...

openlabs docker-wkhtmltopdf-aas up to commit 9f50579 CVE