Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2026-39824

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows_CVE-2026-39824

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 1...

golang.org/x/sys golang.org/x/sys/windows CVE
LOW 3.5 CVE-2026-42448

wormhole receive, with –output pointing at an existing directory can be path-traversed_CVE-2026-42448

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traver...

magic-wormhole magic-wormhole < 0.24.0 CVE
LOW 2.3 CVE-2026-9568

ThingsBoard YAML provision getGatewayDockerComposeFile code injection_CVE-2026-9568

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file...

n/a ThingsBoard 4.3.1.0 CVE
LOW 3.1 CVE-2026-47716

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known_CVE-2026-47716

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in th...

bugsink bugsink < 2.2.0 CVE
LOW 3.1 CVE-2026-47715

Bugsink: Issue event views can show an event from another project if its UUID is known_CVE-2026-47715

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affec...

bugsink bugsink < 2.2.0 CVE
LOW 3.8 CVE-2026-44410

Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE_CVE-2026-44410

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviati...

ZTE ZXUniPOS NDS-LTE V24.40.40 CVE
LOW 1.8 CVE-2025-71310

CVE-2025-71310_CVE-2025-71310

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious ...

BackdropCMS GDPR cookies module for Backdrop CMS CVE
LOW 3.7 CVE-2026-48847

CVE-2026-48847_CVE-2026-48847

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisonin...

Roundcube Webmail 1.6.0 CVE
LOW 3.7 CVE-2026-48852

CVE-2026-48852_CVE-2026-48852

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

PuTTY PuTTY 0.71 CVE
LOW 3.1 CVE-2026-48851

CVE-2026-48851_CVE-2026-48851

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authen...

PuTTY PuTTY 0.77 CVE