Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-57452

Vim: Out-of-bounds Read with libsodium-encrypted Files_CVE-2026-57452

Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (x...

vim vim < 9.2.0671 CVE
MEDIUM 5.3 CVE-2026-57451

Vim: Out-of-bounds Read in Text Property Count_CVE-2026-57451

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline ...

vim vim < 9.2.0670 CVE
MEDIUM 5.7 CVE-2026-55895

Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename_CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the ...

vim vim < 9.2.0663 CVE
MEDIUM 5.5 CVE-2026-55892

Vim: Out-of-bounds Write in Spell File Prefix Dump_CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iter...

vim vim < 9.2.0662 CVE
MEDIUM 5.7 CVE-2026-55693

Vim: Out-of-bounds Write in Spell File Word Count_CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fiel...

vim vim < 9.2.0653 CVE
MEDIUM 5.3 CVE-2026-54036

LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification_CVE-2026-54036

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called...

danny-avila LibreChat < 0.8.4-rc1 CVE
MEDIUM 6.7 CVE-2026-4522

CVE-2026-4522_CVE-2026-4522

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYP...

HYPR Passwordless CVE
MEDIUM 5.5 8FA4E1EF-9BCF-

Exploit for CVE-2025-61155_8FA4E1EF-9BCF-5027-85E0-2F420F5171B6

CVE-2025-61155 — Arbitrary Process Termination in GameDriverX64.sys A signed kernel-mode anti-cheat driver — GameDriverX64.sys, shipped with Tower ...

N/A N/A GITHUBEXPLOIT
MEDIUM 4.3 CVE-2026-42005

Insufficient input validation of internal web server_CVE-2026-42005

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The intern...

PowerDNS Authoritative 4.9.0 CVE
MEDIUM 6.4 CVE-2026-54226

Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS_CVE-2026-54226

A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16...

Apache Software Foundation Apache Kvrocks 2.6.0 CVE