Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.6 CVE-2026-8296

CVE-2026-8296_CVE-2026-8296

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

Octopus Deploy Octopus Server 2023.0.0 CVE
MEDIUM 5.3 CVE-2026-56138

Authenticated Path Traversal in AIL framework /objects/item/diff Allows Reading Gzip-Compressed Files_CVE-2026-56138

AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and ...

ail-project ail-framework CVE
HIGH 7.5 CVE-2026-11576

CVE-2026-11576_CVE-2026-11576

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup labe...

Eclipse Foundation Eclipse ThreadX - NetX Duo 6.4.2 CVE
MEDIUM 6.5 CVE-2026-12706

Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()_CVE-2026-12706

A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed ...

Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 CVE
MEDIUM 5.6 CVE-2026-11941

Use-after-free in connection ID iterator and FFI functions_CVE-2026-11941

Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_n...

Cloudflare Quiche 0.20.0 CVE
CRITICAL 9.6 CVE-2026-56142

CVE-2026-56142_CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching a...

JetBrains Hub CVE
CRITICAL 9.8 CVE-2026-56141

CVE-2026-56141_CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable re...

JetBrains Hub CVE
HIGH 7.1 CVE-2026-53915

CVE-2026-53915_CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

JetBrains GoLand CVE
CRITICAL 10 CVE-2026-50242

CVE-2026-50242_CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct da...

JetBrains Hub CVE
CRITICAL 9.4 CVE-2026-44939

Command injection through unsanitized YAML parameter in Rancher_CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanit...

SUSE Rancher 2.14.0 CVE