Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-45389

CVE-2026-45389_CVE-2026-45389

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authenti...

OCaml OCaml-TLS before 2.1.0 CVE
CRITICAL 9.1 CVE-2026-45388

CVE-2026-45388_CVE-2026-45388

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation...

OCaml-TLS Project OCaml-TLS < 2.1.0 CVE
CRITICAL 9.8 CVE-2026-39196

CVE-2026-39196_CVE-2026-39196

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition...

Datadog, Inc Vector v0.54.0 CVE
HIGH 7.5 CVE-2026-39007

CVE-2026-39007_CVE-2026-39007

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-39006

CVE-2026-39006_CVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

SNMP4J SNMP4J-Agent 3.8.3 CVE
CRITICAL 9.8 CVE-2026-38812

CVE-2026-38812_CVE-2026-38812

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an a...

RuoYi Team RuoYi v4.8.2 CVE
CRITICAL 9.8 CVE-2026-38329

CVE-2026-38329_CVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin...

Bludit Bludit CMS 3.18.4 CVE
MEDIUM 6.8 CVE-2026-36933

CVE-2026-36933_CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-36670

CVE-2026-36670_CVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows...

OpenSIPS opensips-cp < 9.3.3 CVE
CRITICAL 9.8 CVE-2026-36537

CVE-2026-36537_CVE-2026-36537

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user...

ThingsBoard ThingsBoard 4.3.0.1 CVE