Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName_CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitiz...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.1 CVE-2026-7890

Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block_CVE-2026-7890

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enab...

Concrete CMS Concrete CMS 5.0 CVE
LOW 3.7 CVE-2026-7837

TOCTOU with root privilege in ad_flush_CVE-2026-7837

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, w...

Netatalk Netatalk 3.0.0 CVE
LOW 3.7 CVE-2026-44075

Missing break in DSI OpenSession_CVE-2026-44075

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into ...

Netatalk Netatalk 1.5.0 CVE
LOW 3.7 CVE-2026-44074

Bitwise OR of errno values_CVE-2026-44074

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occ...

Netatalk Netatalk 2.1.0 CVE
LOW 3.7 CVE-2026-44071

FORTIFY_SOURCE disabled_CVE-2026-44071

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing...

Netatalk Netatalk 3.1.2 CVE
LOW 3.1 CVE-2026-44057

Dead bounds check in Spotlight RPC unmarshaller_CVE-2026-44057

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effectiv...

Netatalk Netatalk 3.0.0 CVE
LOW 3.1 CVE-2026-7836

hextoint macro uppercase bug_CVE-2026-7836

In Netatalk 2.0.0 through 4.4.2, hextoint macro uppercase bug. Fixed in 4.5.0.

Netatalk Netatalk 2.0.0 CVE
LOW 3.1 CVE-2026-7835

Format string argument mismatch_CVE-2026-7835

In Netatalk 3.0.3 through 4.4.2, format string argument mismatch. Fixed in 4.5.0.

Netatalk Netatalk 3.0.3 CVE
LOW 2.5 CVE-2026-44072

system() after failed chdir()_CVE-2026-44072

In Netatalk 2.2.1 through 4.4.2, system() after failed chdir(). Fixed in 4.5.0.

Netatalk Netatalk 2.2.1 CVE