Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-12289

Privilege escalation in the Graphics: WebRender component_CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
MEDIUM 6.3 CVE-2026-9307

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities_CVE-2026-9307

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Conn...

Rockwell Automation CompactLogix 5370 V36 CVE
HIGH 8.2 CVE-2026-48780

Forem vulnerable to bypass of email address domain restrictions_CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to byp...

forem forem < a2ab6d4 CVE
HIGH 7.7 CVE-2026-47684

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP_CVE-2026-47684

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP bloc...

Sync-in server < 2.3.0 CVE
HIGH 7.5 CVE-2026-12398

Galaxy_ng: shell injection in legacy role import via unsanitized git ref names_CVE-2026-12398

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitize...

Red Hat Red Hat Ansible Automation Platform 2 CVE
HIGH 8.7 CVE-2026-11317

Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP_CVE-2026-11317

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is se...

Rockwell Automation CompactLogix, ControlLogix Versions prior to 34.016, 35.015, 36.012 CVE
MEDIUM 6.9 CVE-2026-10831

Improper Authorization of Break Signal Commands in Devices_CVE-2026-10831

A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not pr...

Moxa NPort 6000 Series 1.0 CVE
MEDIUM 4.2 CVE-2026-10640

Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)_CVE-2026-10640

Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-inte...

zephyrproject zephyr 3.3.0 CVE
MEDIUM 4.8 CVE-2026-10639

Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`_CVE-2026-10639

In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send...

zephyrproject zephyr 1.14.0 CVE
MEDIUM 5.9 CVE-2026-10638

Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error_CVE-2026-10638

subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_r...

zephyrproject zephyr 4.2.0 CVE