Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-22313

OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector_CVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vuln...

Radiflow iSAP Smart Collector 3.07-1 CVE
CRITICAL 9.8 CVE-2026-50890

CVE-2026-50890_CVE-2026-50890

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This v...

Bernd Bestel grocy v4.6.0 CVE
CRITICAL 9.1 CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read_CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argumen...

PEVANS Socket CVE
CRITICAL 9.1 CVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce_CVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of th...

BIAFRA Dancer2::Plugin::Auth::OAuth CVE
CRITICAL 9.1 CVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery_CVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-sign...

TIMLEGGE Crypt::DSA CVE
CRITICAL 9.3 CVE-2026-53776

Perry < 0.5.1166 JWT Expiration Bypass via verify_decode_CVE-2026-53776

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the uncondition...

PerryTS perry CVE
CRITICAL 9.1 CVE-2026-50887

CVE-2026-50887_CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resou...

shlink shlink v5.0.1 CVE
CRITICAL 9.1 CVE-2026-50886

CVE-2026-50886_CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafte...

Project Firefly Project Firefly III v6.5.9 CVE
CRITICAL 9.6 CVE-2026-50883

CVE-2026-50883_CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a cra...

matze matze wastebin v3.4.1 CVE
CRITICAL 9.8 CVE-2026-50872

CVE-2026-50872_CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sens...

fossar selfoss v2.20-SNAPSHOT CVE