Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-44948

Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler_CVE-2026-44948

A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0...

SUSE Rancher 0.12.0 CVE
MEDIUM 4.3 CVE-2026-13455

PostgreSQL Anonymizer: Unrestricted function can leak the secret salt_CVE-2026-13455

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed...

DALIBO PostgreSQL Anonymizer 1 CVE
MEDIUM 6.5 CVE-2026-9263

Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets_CVE-2026-9263

The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO...

zephyrproject zephyr 3.3.0 CVE
HIGH 7.3 CVE-2026-8864

HP Fan Control App – Potential Escalation of Privilege_CVE-2026-8864

The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mit...

HP Inc. HP Fan Control App CVE
HIGH 8.1 CVE-2026-58377

JeecgBoot 3.9.2 – Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys_CVE-2026-58377

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, ...

jeecgboot JeecgBoot CVE
HIGH 7.6 CVE-2026-58376

Dolibarr – SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints_CVE-2026-58376

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrar...

Dolibarr dolibarr CVE
CRITICAL 9.3 CVE-2026-58138

Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators_CVE-2026-58138

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbit...

conductor-oss conductor 3.21.21 CVE
HIGH 7.2 CVE-2026-10513

Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties_CVE-2026-10513

The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' ...

pfefferle Webmention CVE
NONE 871DDD96-CF98-

stack-buffer-overflow-lab_871DDD96-CF98-5B7C-99B6-28D1C125145C

Stack Buffer Overflow Lab Overview This project demonstrates a stack-based buffer overflow vulnerability and explores how memory corruption can be ...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 28C8120C-CE6C-

Exploit for Write-what-where Condition in Linux Linux_Kernel_28C8120C-CE6C-515B-80F8-7917AC287FB6

CVE-KERNEL · Linux Kernel LPE Chain Multi-CVE Local Privilege Escalation chain for Linux kernel vulnerabilities uid=1000 → root via xfrm-ESP, RxRPC...

N/A N/A GITHUBEXPLOIT