Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-44219

ciguard: SCA HTTP client reads response body without size cap_CVE-2026-44219

ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyzer/sca/osv.py and src/cigua...

Jo-Jo98 ciguard >= 0.6.0, < 0.8.2 CVE
LOW 3 CVE-2026-44218

ciguard: Container image runs as root (no USER directive)_CVE-2026-44218

ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard container image inherits the d...

Jo-Jo98 ciguard >= 0.1.0, < 0.8.2 CVE
LOW 3.4 CVE-2026-34685

Adobe Commerce | Improper Input Validation (CWE-20)_CVE-2026-34685

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch — ticket says '...

Adobe Adobe Commerce CVE
LOW 2.1 CVE-2026-44278

CVE-2026-44278_CVE-2026-44278

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may all...

Fortinet FortiClientWindows 7.4.0 CVE
LOW 2.1 CVE-2026-43930

Parse Server: MFA SMS one-time password accepted twice under concurrent login_CVE-2026-43930

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race c...

parse-community parse-server >= 9.0.0, < 9.9.0-alpha.2 CVE
LOW 3.1 CVE-2026-40020

CVE-2026-40020_CVE-2026-40020

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes f...

Open-Xchange GmbH OX Dovecot Pro CVE
LOW 2.9 CVE-2026-32684

CVE-2026-32684_CVE-2026-32684

The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could o...

Hikvision Hik-Connect APP V6.10.x CVE
LOW 3.3 CVE-2026-41530

CVE-2026-41530_CVE-2026-41530

The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product...

Chitora soft Lhaz 2.6.3 and earlier CVE
LOW 3.4 CVE-2026-40131

SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library_CVE-2026-40131

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parame...

SAP_SE SAP HANA Deployment Infrastructure (HDI) deploy library XS_HDI_DEPLOYER 1.00 CVE
LOW 3.2 CVE-2026-45362

CVE-2026-45362_CVE-2026-45362

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Sangoma Switchvox CVE