Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2026-6657

CORS Origin Validation Bypass in jupyter-server_CVE-2026-6657

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` co...

jupyter jupyter/jupyter unspecified CVE
MEDIUM 5.9 CVE-2026-42320

GLPI vulnerable to arbitrary file access_CVE-2026-42320

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read a...

glpi-project glpi >= 11.0.0, < 11.0.7 CVE
MEDIUM 6.3 CVE-2026-3276

Potential DoS via quadratic complexity in unicodedata.normalize()_CVE-2026-3276

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters wi...

Python Software Foundation CPython CVE
MEDIUM 6.3 CVE-2026-35716

CVE-2026-35716_CVE-2026-35716

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers t...

n/a n/a n/a CVE
MEDIUM 6.9 CVE-2026-47325

Weak password policy in ProjectsAndPrograms school-management-system_CVE-2026-47325

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s da...

ProjectsAndPrograms school-management-system 6b6fae5 CVE
MEDIUM 5.1 CVE-2026-47324

Stored XSS in Multiple Points in ProjectsAndPrograms school-management-system_CVE-2026-47324

ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers obj...

ProjectsAndPrograms school-management-system 6b6fae5 CVE
MEDIUM 5.3 CVE-2026-44545

Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service_CVE-2026-44545

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both ...

djangoproject daphne 4.2.0 CVE
MEDIUM 6.3 CVE-2026-35717

CVE-2026-35717_CVE-2026-35717

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers ...

n/a n/a n/a CVE
MEDIUM 4.8 CVE-2026-10722

cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow_CVE-2026-10722

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadColle...

cilium ebpf 0.1 CVE
MEDIUM 5.3 CVE-2026-5078

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user_CVE-2026-5078

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to ...

morgan morgan 1.2.0 CVE