Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-38329

CVE-2026-38329_CVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin...

Bludit Bludit CMS 3.18.4 CVE
MEDIUM 6.8 CVE-2026-36933

CVE-2026-36933_CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-36670

CVE-2026-36670_CVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows...

OpenSIPS opensips-cp < 9.3.3 CVE
CRITICAL 9.8 CVE-2026-36537

CVE-2026-36537_CVE-2026-36537

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user...

ThingsBoard ThingsBoard 4.3.0.1 CVE
HIGH 7.8 CVE-2026-36213

CVE-2026-36213_CVE-2026-36213

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2026-30121

CVE-2026-30121_CVE-2026-30121

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

remotion-dev remotion v4.0.409 CVE
CRITICAL 9.8 CVE-2026-30120

CVE-2026-30120_CVE-2026-30120

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

remotion-dev remotion-dev v4.0.409 CVE
MEDIUM 6.3 CVE-2025-70102

CVE-2025-70102_CVE-2025-70102

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-...

n/a n/a n/a CVE
HIGH 8 CVE-2025-68713

CVE-2025-68713_CVE-2025-68713

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows unt...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-53900

Cookie injection was possible when opening a PDF link_CVE-2026-53900

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site...

Mozilla Firefox for iOS 152.0 CVE