Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-37454

CVE-2026-37454_CVE-2026-37454

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DE...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37453

CVE-2026-37453_CVE-2026-37453

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38637

CVE-2026-38637_CVE-2026-38637

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37452

CVE-2026-37452_CVE-2026-37452

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-8380

Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion_CVE-2026-8380

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion,...

Unknown Frontend File Manager Plugin CVE
HIGH 7.7 CVE-2026-10835

SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection_CVE-2026-10835

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before ...

Unknown SALESmanago & Leadoo CVE
HIGH 7.5 CVE-2026-49486

Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)_CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control...

Apache Software Foundation Apache Airflow FTP provider CVE
HIGH 7.5 CVE-2026-11702

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes_CVE-2026-11702

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before for...

DAVIDO Bytes::Random::Secure::Tiny CVE
HIGH 7.5 CVE-2026-11625

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes_CVE-2026-11625

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, o...

DAVIDO Bytes::Random::Secure CVE
HIGH 7.3 CVE-2026-57915

Apache Kerby: Kerberos Pre-Authentication Bypass_CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users...

Apache Software Foundation Apache Kerby CVE