Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-57288

CVE-2026-57288_CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI...

Jenkins Project Jenkins Active Directory Plugin CVE
LOW 2.7 CVE-2026-10753

Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update_CVE-2026-10753

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-priv...

Unknown Site Kit by Google CVE
LOW 1.1 CVE-2026-13140

Stored Cross-Site Scripting in Canarytokens.org_CVE-2026-13140

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledg...

Thinkst Applied Research Canarytokens sha-4116b92cb CVE
LOW 2.3 CVE-2026-46554

NocoDB: Stale Auth Cache After API Token Deletion_CVE-2026-46554

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their ca...

nocodb nocodb < 2026.04.4 CVE
LOW 2.1 CVE-2026-46553

NocoDB: Attachment Size Limit Bypass via Upload-by-URL_CVE-2026-46553

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE agai...

nocodb nocodb < 2026.04.1 CVE
LOW 2 CVE-2026-46549

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation_CVE-2026-46549

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_reso...

nocodb nocodb < 2026.04.1 CVE
LOW 2.2 CVE-2026-54327

Pi: Race condition in auth.json writes could expose stored credentials_CVE-2026-54327

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the f...

earendil-works pi >= 0.74.0, < 0.78.1 CVE
LOW 2.5 CVE-2026-54326

Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass_CVE-2026-54326

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not cons...

earendil-works pi >= 0.74.0, < 0.78.1 CVE
LOW 2.3 CVE-2026-47388

NocoDB: Missing Ownership Check in MCP Attachment Read_CVE-2026-47388

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment pat...

nocodb nocodb < 2026.05.1 CVE
LOW 3.7 CVE-2026-56968

CVE-2026-56968_CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosur...

GNU GNU SASL CVE