Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.2 CVE-2025-52430

QTS, QuTS hero_CVE-2025-52430

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.2 CVE-2025-52426

QTS, QuTS hero_CVE-2025-52426

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.3 CVE-2025-44013

QTS, QuTS hero_CVE-2025-44013

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user acco...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 2 CVE-2026-21437

eopkg vulnerable to package file list integrity bypass_CVE-2026-21437

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked b...

getsolus eopkg < 4.4.0 CVE
LOW 3.4 CVE-2025-69412

CVE-2025-69412_CVE-2025-69412

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might all...

KDE messagelib CVE
LOW 2.5 CVE-2025-66861

CVE-2025-66861_CVE-2025-66861

An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via c...

n/a n/a n/a CVE
LOW 1.9 CVE-2025-11964

OOBW in utf_16le_to_utf_8_truncated() in libpcap_CVE-2025-11964

On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 byt...

The Tcpdump Group libpcap 1.10.0 CVE
LOW 1.9 CVE-2025-11961

OOBR and OOBW in pcap_ether_aton() in libpcap_CVE-2025-11961

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument m...

The Tcpdump Group libpcap CVE
LOW 1.3 CVE-2025-14986

ExecuteMultiOperation Namespace Policy Bypass_CVE-2025-14986

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWork...

Temporal Temporal 1.24.0 CVE
LOW 2.7 CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221_CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the f...

ruby uri CVE