Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-51845

CVE-2026-51845_CVE-2026-51845

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.

Tenda Tenda AC7 v15.03.06.44 CVE
CRITICAL 9.8 CVE-2026-51844

CVE-2026-51844_CVE-2026-51844

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.

Tenda Tenda AC7 v15.03.06.44 CVE
CRITICAL 9.8 CVE-2026-51843

CVE-2026-51843_CVE-2026-51843

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

Tenda Tenda AC7 v15.03.06.44 CVE
MEDIUM 6.1 CVE-2026-4110

Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list_CVE-2026-4110

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page,...

Unknown ultimate-woocommerce-auction-pro CVE
MEDIUM 5.3 CVE-2026-10530

Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token_CVE-2026-10530

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowin...

Unknown Pie Register CVE
HIGH 8.1 CVE-2025-66336

Apache Doris MCP Server: SQL injection leading the authentication bypass_CVE-2025-66336

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated i...

Apache Software Foundation Apache Doris MCP Server 0.1.0 CVE
MEDIUM 5.4 CVE-2025-62198

Apache Atlas: Stored XSS in Create Entity page_CVE-2025-62198

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2....

Apache Software Foundation Apache Atlas CVE
HIGH 7.5 CVE-2025-66389

CVE-2025-66389_CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_web...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-10845

IBM WebSphere Application Server is affected by an authentication bypass vulnerability_CVE-2026-10845

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicat...

IBM WebSphere Application Server 8.5.0 CVE
HIGH 7 CVE-2026-56109

ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c_CVE-2026-56109

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows ...

alsa-project alsa-lib CVE