Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-25089

CVE-2026-25089_CVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5...

Fortinet FortiSandbox 5.0.0 CVE
CRITICAL 9.9 CVE-2026-10523

CVE-2026-10523_CVE-2026-10523

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated ...

ivanti Sentry R10.5.2 CVE
CRITICAL 10 CVE-2026-10520

CVE-2026-10520_CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to ach...

ivanti Sentry R10.5.2 CVE
CRITICAL 9.8 CVE-2026-49841

FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read_CVE-2026-49841

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation t...

signalwire freeswitch < 1.11.1 CVE
CRITICAL 9.1 CVE-2026-49840

FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing_CVE-2026-49840

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation t...

signalwire freeswitch < 1.11.1 CVE
CRITICAL 9.1 CVE-2025-10263

CVE-2025-10263_CVE-2025-10263

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cor...

Arm C1-Ultra CVE
CRITICAL 9.8 CVE-2026-29167

Apache HTTP Server: mod_ldap per-dir use-after-free_CVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 ...

Apache Software Foundation Apache HTTP Server 2.4.0 CVE
CRITICAL 9.8 CVE-2026-7486

SQLi in Netcad’s E-İmar_CVE-2026-7486

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Inject...

Netcad Software Inc. E-İmar 2.10.1.0 CVE
CRITICAL 9.1 CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access_CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databas...

Apache Software Foundation Apache HTTP Server 2.4.67 and earlier CVE
CRITICAL 9.6 CVE-2026-11697

CVE-2026-11697_CVE-2026-11697

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbo...

Google Chrome 149.0.7827.103 CVE