Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-50235

Lyrion Music Server 9.2.0 Reflected XSS via search Parameters_CVE-2026-50235

Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user...

LMS Community Lyrion Music Server 9.2.0 CVE
HIGH 8.7 CVE-2026-50234

Lyrion Music Server 9.2.0 Path Traversal File Read_CVE-2026-50234

Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting direc...

LMS Community Lyrion Music Server 9.2.0 CVE
MEDIUM 6.9 CVE-2026-50233

Lyrion Music Server 9.2.0 Arbitrary Directory Listing_CVE-2026-50233

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (T...

LMS Community Lyrion Music Server 9.2.0 CVE
MEDIUM 5.1 CVE-2026-50232

Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags_CVE-2026-50232

Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file...

LMS Community Lyrion Music Server 9.2.0 CVE
MEDIUM 5.1 CVE-2026-50231

Lyrion Music Server 9.2.0 Unauthenticated Stored XSS via server.log_CVE-2026-50231

Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject m...

LMS Community Lyrion Music Server 9.2.0 CVE
MEDIUM 5.1 CVE-2026-50230

Lyrion Music Server 9.2.0 Reflected XSS via server.log_CVE-2026-50230

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers...

LMS Community Lyrion Music Server 9.2.0 CVE
HIGH 7.1 CVE-2026-11369

IDOR in Comment API Allows Cross-Process Comment Read and Write_CVE-2026-11369

The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the reque...

linqi GmbH linqi CVE
LOW 2 CVE-2026-11330

thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash_CVE-2026-11330

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the fil...

thedotmack claude-mem 11.0.0 CVE
CRITICAL 9.1 CVE-2026-6209

Improper Access Control in in HAVELSAN’s Geographic Tracking System_CVE-2026-6209

Improper Access Control, Missing Authorization vulnerability in HAVELSAN Inc. Geographic Tracking System allows Accessing Functionality Not Properl...

HAVELSAN Inc. Geographic Tracking System CVE
CRITICAL 9.1 CVE-2026-6208

IDOR in in HAVELSAN’s Geographic Tracking System_CVE-2026-6208

Authorization bypass through User-Controlled key vulnerability in HAVELSAN Inc. Geographic Tracking System allows Exploitation of Trusted Identifie...

HAVELSAN Inc. Geographic Tracking System CVE