Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2026-44726

Deno: TLS retry copies stale upgrade hook, risking plaintext traffic_CVE-2026-44726

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a T...

denoland deno >= 2.0.0, < 2.7.8 CVE
HIGH 7.1 CVE-2025-71382

MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering_CVE-2025-71382

MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a d...

ArtifexSoftware mupdf CVE
HIGH 7.5 CVE-2025-61029

CVE-2025-61029_CVE-2025-61029

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61024

CVE-2025-61024_CVE-2025-61024

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted ...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-54324

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join_CVE-2026-54324

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant author...

daytonaio daytona < 0.185.0 CVE
MEDIUM 5.9 CVE-2026-54323

Daytona: Git credential leak via git clone with TLS verification disabled_CVE-2026-54323

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clon...

daytonaio daytona < 0.185.0 CVE
HIGH 7.1 CVE-2026-54318

Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location_CVE-2026-54318

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager Broa...

home-assistant core < 2026.5.3 CVE
HIGH 7.6 CVE-2026-54317

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN_CVE-2026-54317

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regi...

home-assistant core < 2026.6.0 CVE
CRITICAL 9 CVE-2026-54157

LobeHub: Unauthenticated SSRF in `/webapi/proxy`_CVE-2026-54157

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy e...

lobehub lobehub < 2.1.57 CVE
CRITICAL 9.6 CVE-2026-53662

immich: One-click account takeover via XSS in login page continue redirect_CVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting ...

immich-app immich >= main@4ffa26c9, < main@4eb1003 CVE