Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2026-50229

Apache Tomcat: XSS in number guess example_CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-51218

CVE-2026-51218_CVE-2026-51218

A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial o...

n/a n/a n/a CVE
MEDIUM 4.9 CVE-2026-9576

Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export_CVE-2026-9576

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export...

Unknown Fluent Booking CVE
MEDIUM 5.9 CVE-2026-11581

Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption_CVE-2026-11581

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it ...

Unknown Kali Forms — Contact Form & Drag-and-Drop Builder CVE
MEDIUM 6.5 CVE-2025-24816

An Improper Access Control vulnerability in Nokia MantaRay NM_CVE-2025-24816

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation cou...

Nokia MantaRay NM <25R2-NM CVE
MEDIUM 5.3 CVE-2026-57079

Net::BitTorrent versions through 2.0.1 for Perl write files outside the download directory via path traversal in peer-supplied metadata_CVE-2026-57079

Net::BitTorrent versions through 2.0.1 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitT...

SANKO Net::BitTorrent CVE
MEDIUM 6.5 CVE-2026-58374

CVE-2026-58374_CVE-2026-58374

In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows ...

w1.fi hostapd CVE
MEDIUM 5.9 CVE-2026-58015

Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive_CVE-2026-58015

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_c...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 6.5 CVE-2026-58013

Glib: buffer over-read in glib/giochannel.c via “g_io_channel_read_line_backend”_CVE-2026-58013

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator w...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 6.5 CVE-2026-58012

Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()_CVE-2026-58012

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-chang...

Red Hat Red Hat Enterprise Linux 10 CVE