Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 243CDB42-BE28-

Exploit for CVE-2026-2256_243CDB42-BE28-5810-BB45-078630950EB9

CVE-2026-2256-Threat-Model----ms-agent-Command-Injection...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-42507

Arbitrary inputs are included in errors without any escaping in net/textproto_CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject ...

Go standard library net/textproto CVE
MEDIUM 6.5 CVE-2026-35718

CVE-2026-35718_CVE-2026-35718

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers t...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-33553

CVE-2026-33553_CVE-2026-33553

Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-30586

CVE-2026-30586_CVE-2026-30586

Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Mem...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2025-70101

CVE-2025-70101_CVE-2025-70101

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-70100

CVE-2025-70100_CVE-2025-70100

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause ...

n/a n/a n/a CVE
MEDIUM 5 CVE-2025-60477

CVE-2025-60477_CVE-2025-60477

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2026-39107

CVE-2026-39107_CVE-2026-39107

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or en...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-36615

CVE-2026-36615_CVE-2026-36615

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents t...

n/a n/a n/a CVE