Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.7 CVE-2026-25624

Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting_CVE-2026-25624

An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Ari...

Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CVE
MEDIUM 6 CVE-2026-25623

Arista Edge Threat Management NGFW UI Arbitrary Command Execution_CVE-2026-25623

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Genera...

Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CVE
MEDIUM 6 CVE-2026-25622

Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection_CVE-2026-25622

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). O...

Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CVE
MEDIUM 6 CVE-2026-25621

Arista Edge Threat Management NGFW Reports Application Insecure Input Validation_CVE-2026-25621

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure...

Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) 17.4.0 CVE
MEDIUM 6 CVE-2026-25620

Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection_CVE-2026-25620

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista ...

Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) 17.4.0 CVE
MEDIUM 6.5 CVE-2026-37737

CVE-2026-37737_CVE-2026-37737

sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match wit...

n/a n/a n/a CVE
MEDIUM 6.1 ZSL-2026-5988

Lyrion Music Server 9.2.0 (server.log) Unauthenticated Reflected XSS_ZSL-2026-5988

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
MEDIUM 6.1 ZSL-2026-5993

Lyrion Music Server 9.2.0 (search.*) Multiple Script Insertions_ZSL-2026-5993

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
MEDIUM 6.9 ZSL-2026-5991

Lyrion Music Server 9.2.0 Arbitrary Directory Listing_ZSL-2026-5991

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
MEDIUM 5.3 CVE-2026-38978

CVE-2026-38978_CVE-2026-38978

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

n/a n/a n/a CVE