Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-0925

Tanium addressed an improper input validation vulnerability in Discover._CVE-2026-0925

Tanium addressed an improper input validation vulnerability in Discover.

Tanium Discover 4.10.134 CVE
LOW 1 CVE-2026-1408

Beetel 777VR1 UART weak password_CVE-2026-1408

A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface...

Beetel 777VR1 01.00.09 CVE
LOW 1 CVE-2026-1409

Beetel 777VR1 UART excessive authentication_CVE-2026-1409

A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown processing of the component...

Beetel 777VR1 01.00.09 CVE
LOW 1 CVE-2026-1407

Beetel 777VR1 UART information disclosure_CVE-2026-1407

A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the component UART Interface. Perf...

Beetel 777VR1 01.00.09 CVE
LOW 2.7 CVE-2026-24130

Moonraker with LDAP Enabled Allows Malicious Search Filter Injection_CVE-2026-24130

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "...

Arksine moonraker < 0.10.0 CVE
LOW 2.9 CVE-2026-24515

CVE-2026-24515_CVE-2026-24515

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

libexpat project libexpat CVE
LOW 2.7 CVE-2026-24140

MyTube has Mass Assignment via Settings Management_CVE-2026-24140

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the set...

franklioxygen MyTube < 1.7.79 CVE
LOW 3.7 CVE-2026-0633

MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value_CVE-2026-0633

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure ...

roxnor MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor * CVE
LOW 2.4 CVE-2025-68132

EVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driver_CVE-2025-68132

EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[v...

EVerest everest-core < 2025.12.0 CVE
LOW 3.7 CVE-2026-23996

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection_CVE-2026-23996

FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verif...

Athroniaeth fastapi-api-key < 1.1.0 CVE