Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2026-34915

CVE-2026-34915_CVE-2026-34915

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to explo...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-34913

CVE-2026-34913_CVE-2026-34913

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier cou...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-34912

CVE-2026-34912_CVE-2026-34912

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier...

Revive Adserver CVE
MEDIUM 4.4 CVE-2025-13162

Advant Master Online Builder DLL vulnerability_CVE-2025-13162

Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: throug...

ABB Control Builder A CVE
MEDIUM 4 CVE-2026-57053

CVE-2026-57053_CVE-2026-57053

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_inte...

GNU libidn CVE
MEDIUM 4.3 CVE-2026-55517

Deno: Denial of service via non-ASCII bytes in WebSocket response headers_CVE-2026-55517

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed...

denoland deno < 2.7.5 CVE
MEDIUM 6 CVE-2026-54316

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch_CVE-2026-54316

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the ...

anthropics claude-code >= 0.2.54, < 2.1.163 CVE
MEDIUM 5.3 CVE-2026-54022

Open WebUI: Any authenticated user can read other users’ private notes via Socket.IO_CVE-2026-54022

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.I...

open-webui open-webui < 0.8.11 CVE
MEDIUM 6.3 CVE-2026-54021

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter_CVE-2026-54021

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed ...

open-webui open-webui < 0.9.6 CVE
MEDIUM 6.5 CVE-2026-54019

Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode_CVE-2026-54019

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-leve...

open-webui open-webui < 0.9.6 CVE