Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-56450

AIL Framework – Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes_CVE-2026-56450

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification st...

ail project ail framework CVE
MEDIUM 4.3 MS:CVE-2026-12446

Chromium: CVE-2026-12446 Insufficient data validation in Passwords_MS:CVE-2026-12446

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 5.4 CVE-2026-10601

Path Traversal in Tempo and Loki Data Source Plugins — Credential Leakage and Admin Endpoint Access_CVE-2026-10601

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, ena...

Grafana Grafana OSS 11.6.0 CVE
MEDIUM 5.4 CVE-2025-33128

IBM Engineering Lifecycle Management – Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed_CVE-2025-33128

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting....

IBM Engineering Workflow Management 7.0.3 CVE
MEDIUM 6 CVE-2025-2669

Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data._CVE-2025-2669

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform ope...

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 4.8.0 CVE
MEDIUM 5.1 CVE-2026-12862

XLSX formula injection in exports_CVE-2026-12862

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the env...

pretix Venueless 0.0.0 CVE
MEDIUM 5.1 CVE-2026-12580

Digiwin|EasyFlow .NET – Stored Cross-Site Scripting_CVE-2026-12580

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent Ja...

Digiwin EasyFlow .NET CVE
MEDIUM 6.3 CVE-2026-54665

Apache NiFi: Missing Validation for Proxy Host Headers_CVE-2026-54665

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standar...

Apache Software Foundation Apache NiFi 0.0.1 CVE
MEDIUM 5.2 CVE-2026-44913

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL_CVE-2026-44913

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQ...

Apache Software Foundation Apache NiFi 1.2.0 CVE
MEDIUM 6.9 CVE-2026-11748

CVE-2026-11748_CVE-2026-11748

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitut...

LY Corporation Central Dogma 0.84.0 CVE