Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-9640

LXD Snapshot Import Privilege Escalation Vulnerability_CVE-2026-9640

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of proj...

Canonical LXD 5.21.0 CVE
HIGH 7.1 CVE-2026-47214

Docling: Unsafe URI and Path Handling in HTML Backend_CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the...

docling-project docling < 2.94.0 CVE
HIGH 8.4 CVE-2026-12411

Broken Access Control in Canonical LXD DevLXD API_CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another ...

Canonical lxd 6.6 CVE
HIGH 8.7 CVE-2026-57518

Pagekit CMS 1.0.18 Privilege Escalation via UserApiController_CVE-2026-57518

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escala...

pagekit pagekit 1.0.18 CVE
HIGH 7.5 CVE-2026-57231

Podman: Malformed Image can trick podman run into leaking host environment variables into the container_CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a k...

podman-container-tools podman >= 1.8.1, < 5.8.4 CVE
HIGH 8.5 CVE-2026-56663

AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access_CVE-2026-56663

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an auth...

Significant-Gravitas AutoGPT < 0.6.52 CVE
HIGH 7.5 CVE-2026-55677

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files_CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches rout...

labstack echo < 4.15.3 CVE
HIGH 7.8 CVE-2025-60464

CVE-2025-60464_CVE-2025-60464

A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to ca...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38640

CVE-2026-38640_CVE-2026-38640

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a...

n/a n/a n/a CVE
HIGH 8.3 CVE-2026-13281

CVE-2026-13281_CVE-2026-13281

Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially...

Google Chrome 149.0.7827.201 CVE