Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.7 CVE-2026-7532

iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined_CVE-2026-7532

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allo...

wolfSSL wolfSSL CVE
MEDIUM 5.9 CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures to be accepted_CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged si...

wolfSSL wolfSSL 3.15.5 CVE
MEDIUM 6.1 CVE-2026-40080

Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect_CVE-2026-40080

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring c...

Cacti cacti < 1.2.31 CVE
MEDIUM 6.3 CVE-2026-48946

Joomla Extension – getk2.com – Privileged RCE vulnerability in K2 extension for Joomla < 2.26_CVE-2026-48946

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 5.3 CVE-2026-48945

Joomla Extension – getk2.com – Privileged RCE vulnerability in K2 extension for Joomla < 2.26_CVE-2026-48945

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48944

Joomla Extension – getk2.com – Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26_CVE-2026-48944

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48943

Joomla Extension – getk2.com – Authenticated user property mass-assignment in K2 extension for Joomla < 2.26_CVE-2026-48943

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserFor...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48941

Joomla Extension – getk2.com – Unauthenticated folder delete in K2 extension for Joomla < 2.26_CVE-2026-48941

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()`...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 5.3 CVE-2026-28898

CVE-2026-28898_CVE-2026-28898

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTT...

Apple swift-nio-http2 CVE
MEDIUM 5.3 CVE-2026-57521

Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController_CVE-2026-57521

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization...

bitwarden server CVE