Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-2708

Libsoup: libsoup: http request smuggling via duplicate content-length headers_CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/sou...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.3 CVE-2026-41908

OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route_CVE-2026-41908

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without ...

OpenClaw OpenClaw CVE
LOW 3.5 CVE-2026-4512

WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS_CVE-2026-4512

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript stri...

Unknown reCaptcha by WebDesignBy CVE
LOW 3.2 CVE-2026-41988

CVE-2026-41988_CVE-2026-41988

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID versio...

uuidjs uuid CVE
LOW 2.7 CVE-2026-1272

IBM Guardium Data Protection is affected by multiple vulnerabilities_CVE-2026-1272

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

IBM Guardium Data Protection 12.0 CVE
LOW 2.1 CVE-2026-6019

BaseCookie.js_output() does not neutralize embedded characters_CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser...

Python Software Foundation CPython CVE
LOW 3.1 CVE-2026-34067

nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch_CVE-2026-34067

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` ...

nimiq nimiq-transaction < 1.3.0 CVE
LOW 3.3 CVE-2026-35381

uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering_CVE-2026-35381

A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) ...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35379

uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling_CVE-2026-35379

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The imp...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35378

uutils coreutils expr Local Denial of Service via Eager Evaluation of Parenthesized Subexpressions_CVE-2026-35378

A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather t...

Uutils coreutils CVE