Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2026-1237

CVE-2026-1237_CVE-2026-1237

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update da...

Canonical juju CVE
LOW 3.7 CVE-2026-22261

Suricata eve/alert: http1 xff handling can lead to denial of service_CVE-2026-22261

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts no...

OISF suricata < 7.0.14 CVE
LOW 3.7 CVE-2026-24883

CVE-2026-24883_CVE-2026-24883

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a ...

GnuPG GnuPG CVE
LOW 3.7 CVE-2026-24870

Information disclosure in ixray-1.6-stcop_CVE-2026-24870

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

ixray-team ixray-1.6-stcop CVE
LOW 2.8 CVE-2026-1485

Glib: glib: local denial of service via buffer underflow in content type parsing_CVE-2026-1485

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in ...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3.1 CVE-2026-1190

Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata_CVE-2026-1190

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML)...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.1 CVE-2025-9521

Password Confirmation Bypass in Omada Controller_CVE-2025-9521

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, ...

TP-Link Systems Inc. Omada Controller CVE
LOW 3.3 CVE-2025-9615

Networkmanager: networkmanager file access_CVE-2025-9615

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-roo...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3.7 CVE-2026-24656

Apache Karaf: Decanter log-socket collector has deserialization vulnerability_CVE-2026-24656

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authen...

Apache Software Foundation Apache Karaf CVE
LOW 2.1 CVE-2026-24439

Tenda W30E V2 Lacks X-Content-Type-Options Header_CVE-2026-24439

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header ...

Shenzhen Tenda Technology Co., Ltd. W30E V2 CVE