Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 ZSL-2026-5990

Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
MEDIUM 6.9 ZSL-2026-5991

Lyrion Music Server 9.2.0 Arbitrary Directory Listing_ZSL-2026-5991

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 8.7 ZSL-2026-5992

Lyrion Music Server 9.2.0 Path Traversal File Read_ZSL-2026-5992

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 7.2 28BA8DE6-E5F6-

Dirty-cow-exploit_28BA8DE6-E5F6-5EDA-B23F-99DD01F58B76

System Documentation Architecture - Frontend: React 19 + Vite + TailwindCSS 4. - Backend: Express.js REST API with modular routing. - Database: SQL...

N/A N/A GITHUBEXPLOIT
NONE MSF:EXPLOIT-MULTI-

ClickFix Server_MSF:EXPLOIT-MULTI-MISC-CLICKFIX_SERVER-

This creates a Web Server which hosts a ClickFix type exploit. When a user visits the site they are given instructions on pasting our payload into ...

N/A N/A METASPLOIT
MEDIUM 5.3 CVE-2026-38978

CVE-2026-38978_CVE-2026-38978

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37460

CVE-2026-37460_CVE-2026-37460

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a De...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2026-5589

Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem._CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bo...

zephyrproject-rtos Zephyr * CVE
MEDIUM 4.3 CVE-2026-11178

CVE-2026-11178_CVE-2026-11178

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11177

CVE-2026-11177_CVE-2026-11177

Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures ...

Google Chrome 149.0.7827.53 CVE