Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery_CVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-sign...

TIMLEGGE Crypt::DSA CVE
CRITICAL 9.3 CVE-2026-53776

Perry < 0.5.1166 JWT Expiration Bypass via verify_decode_CVE-2026-53776

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the uncondition...

PerryTS perry CVE
CRITICAL 9.1 CVE-2026-50887

CVE-2026-50887_CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resou...

shlink shlink v5.0.1 CVE
CRITICAL 9.1 CVE-2026-50886

CVE-2026-50886_CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafte...

Project Firefly Project Firefly III v6.5.9 CVE
CRITICAL 9.6 CVE-2026-50883

CVE-2026-50883_CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a cra...

matze matze wastebin v3.4.1 CVE
CRITICAL 9.8 CVE-2026-50872

CVE-2026-50872_CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sens...

fossar selfoss v2.20-SNAPSHOT CVE
CRITICAL 9.8 CVE-2026-50871

CVE-2026-50871_CVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers t...

kanishka-linux Reminiscence v0.3.0 CVE
CRITICAL 9.8 CVE-2026-50869

CVE-2026-50869_CVE-2026-50869

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

Bludit Team Bludit v3.19.0 CVE
CRITICAL 9.1 CVE-2026-45390

CVE-2026-45390_CVE-2026-45390

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired ...

OCaml OCaml-tar before 3.4.0 CVE
CRITICAL 9.1 CVE-2026-45389

CVE-2026-45389_CVE-2026-45389

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authenti...

OCaml OCaml-TLS before 2.1.0 CVE