Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-9096

CVE-2026-9096_CVE-2026-9096

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including ...

Casdoor Casdoor CVE
HIGH 8.8 CVE-2026-49298

Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments_CVE-2026-49298

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the wo...

Apache Software Foundation Apache Airflow CVE
HIGH 7.5 CVE-2026-41084

Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation_CVE-2026-41084

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization...

Apache Software Foundation Apache Airflow 3.2.0 CVE
HIGH 7.2 CVE-2026-40961

Apache Airflow: Open Redirect Bypass Vulnerability_CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redir...

Apache Software Foundation Apache Airflow 3.0.0 CVE
HIGH 7.5 CVE-2026-37235

CVE-2026-37235_CVE-2026-37235

FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function vali...

n/a n/a n/a CVE
HIGH 7.8 CVE-2026-0088

CVE-2026-0088_CVE-2026-0088

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. Th...

Google Android 16-qpr2 CVE
HIGH 7.8 CVE-2026-40715

CVE-2026-40715_CVE-2026-40715

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local acc...

Dell ThinOS 10 CVE
HIGH 7.8 CVE-2026-24237

CVE-2026-24237_CVE-2026-24237

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.8 CVE-2026-24221

CVE-2026-24221_CVE-2026-24221

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.1 CVE-2026-1871

Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200_CVE-2026-1871

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header...

TP-Link Systems Inc. Tapo C200 v5 CVE