Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 CVE-2026-50633

Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl_CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is ab...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.1 CVE-2026-50632

Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory_CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, w...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 7.4 CVE-2026-50631

Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing_CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate m...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 6.5 CVE-2026-50630

Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection_CVE-2026-50630

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' p...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 5.3 CVE-2026-50629

Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier_CVE-2026-50629

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control ch...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 6.5 CVE-2026-50623

Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService_CVE-2026-50623

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the securi...

Apache Software Foundation Apache CXF 4.2.0 CVE
LOW 1 CVE-2026-12065

Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme_CVE-2026-12065

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebVi...

Groww Stock, Mutual Fund, Gold App 20260805 CVE
HIGH 8.5 CVE-2026-11967

Arbitrary code execution in MobaXterm Personal Edition (Portable)_CVE-2026-11967

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the ...

Mobatek MobaXterm Personal Edition (Portable) 26.3 CVE
MEDIUM 5.3 CVE-2026-8694

Improper access control on the API documentation endpoint in PowerShell Universal_CVE-2026-8694

Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI sp...

Devolutions PowerShell Universal CVE
HIGH 8.6 CVE-2026-7368

Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization_CVE-2026-7368

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded crede...

Yarbo Yarbo Android/IOS mobile application CVE