Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-53776

Perry < 0.5.1166 JWT Expiration Bypass via verify_decode_CVE-2026-53776

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the uncondition...

PerryTS perry CVE
HIGH 8.8 CVE-2026-44932

indirect remote shell command injection via unsanitized DHCP options in wicked_CVE-2026-44932

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious ...

SUSE wicked CVE
HIGH 8.6 CVE-2026-42089

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation_CVE-2026-42089

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 ...

yeoman environment >= 2.9.0, < 6.0.1 CVE
HIGH 7.8 CVE-2026-24228

CVE-2026-24228_CVE-2026-24228

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of thi...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
HIGH 7.8 CVE-2026-24155

CVE-2026-24155_CVE-2026-24155

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code exec...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
MEDIUM 5.3 CVE-2026-12003

CPython >3.11 Insecure Input Validation resulting in privilege escalation_CVE-2026-12003

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and ...

Python Software Foundation CPython CVE
HIGH 8.6 CVE-2026-10649

Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression_CVE-2026-10649

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2025-71261

Harvester’s SUSE Virtualization Registration Client Vulnerable to MITM and DOS_CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the ...

SUSE Harvester CVE
MEDIUM 6.5 PACKETSTORM:223516

📄 Apache Flink Kubernetes Operator 1.14.0 Server-Side Request Forgery_PACKETSTORM:223516

This is a Metasploit auxiliary module to demonstrate a service-side request forgery vulnerability in Apache Flink Kubernetes Operator version 1.14....

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:223514

📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service_PACKETSTORM:223514

This script is a multi-mode security tool that triggers a denial of service against Apache HTTP Server version 2.4.66 related to a double-free cond...

N/A N/A PACKETSTORM