Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8 CVE-2026-48165

MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side_CVE-2026-48165

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.27 CVE
HIGH 8 CVE-2026-48163

MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)_CVE-2026-48163

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.27 CVE
HIGH 7.8 CVE-2026-47965

Acrobat Reader | Out-of-bounds Write (CWE-787)_CVE-2026-47965

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary ...

Adobe Acrobat Reader CVE
MEDIUM 6 CVE-2026-47225

Improper Search Cache Isolation for Scoped Search API Keys in Typesense_CVE-2026-47225

Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that ...

typesense typesense < 29.1 CVE
MEDIUM 5.4 CVE-2026-47223

NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow_CVE-2026-47223

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bou...

M2Team NanaZip >= 3.0.1000.0, < 6.0.1698.0 CVE
HIGH 8.7 CVE-2026-47216

Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint_CVE-2026-47216

Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in t...

typesense typesense < 29.1 CVE
MEDIUM 5 CVE-2026-44173

MariaDB: FILE privilege was not checked for subqueries in the FROM clause_CVE-2026-44173

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.26 CVE
MEDIUM 6.9 CVE-2026-44172

MariaDB: mysql_real_escape_string() incorrectly handled big5_CVE-2026-44172

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input...

MariaDB server = 3.3.18 CVE
MEDIUM 6.3 CVE-2026-44171

MariaDB: path traversal in mbstream_CVE-2026-44171

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.26 CVE
MEDIUM 6.3 CVE-2026-44170

MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL_CVE-2026-44170

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before ...

MariaDB server >= 10.6.1, < 10.6.26 CVE