Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-56130

Apache Shiro: Remember-me cookie isn’t checked for expiry on the server_CVE-2026-56130

"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, ...

Apache Software Foundation Apache Shiro 1.2.4 CVE
LOW 2.4 CVE-2026-45188

Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling_CVE-2026-45188

Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to u...

Apache Software Foundation Apache Kvrocks 1.0.0 CVE
LOW 3.1 CVE-2026-3176

Missing Authorization in GitLab_CVE-2026-3176

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 18.6 CVE
LOW 3.8 CVE-2026-0934

Incorrect Authorization in GitLab_CVE-2026-0934

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 17.9 CVE
LOW 3.3 CVE-2026-8662

Path Traversal in Rapid7 InsightConnect Compression Plugin_CVE-2026-8662

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to ...

Rapid7 InsightConnect Compression Plugin CVE
LOW 2.9 CVE-2026-39894

Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting_CVE-2026-39894

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtoo...

Cacti cacti < 1.2.31 CVE
LOW 3.5 CVE-2026-52796

Gogs: DoS in rendering issue index pattern_CVE-2026-52796

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting ...

gogs gogs < 0.14.3 CVE
LOW 2.3 CVE-2026-49277

Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation_CVE-2026-49277

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 CVE
LOW 2.3 CVE-2026-45757

Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens_CVE-2026-45757

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 CVE
LOW 1.7 CVE-2026-49246

Jellyfin: Potential MKV attachment filename path traversal to RCE_CVE-2026-49246

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leve...

jellyfin jellyfin < 10.11.10 CVE