Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.8 CVE-2026-6923

Nuvoton – CWE-1300: Improper Protection of Physical Side Channels_CVE-2026-6923

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

Nuvoton NPCT7xx all versions below 7.2.4.0 CVE
LOW 2.3 CVE-2026-44515

Nextcloud News: Authenticated blind SSRF via feed URL_CVE-2026-44515

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (...

nextcloud news < 28.3.0-beta.1 CVE
LOW 2.5 CVE-2026-44348

PoDoFo: Double-free vulnerability in compute_hash_to_sign()_CVE-2026-44348

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/...

podofo podofo >= 1.0.0, < 1.0.4 CVE
LOW 2.6 CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters._CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it...

HCL AION 2.1.0 CVE
LOW 2.3 CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured_CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers ...

HCL AION 2.1.0 CVE
LOW 3 CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication_CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may exp...

HCL AION 2.1.0 CVE
LOW 2.6 CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields._CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information...

HCL AION 2.1.0 CVE
LOW 3.7 CVE-2026-6638

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name_CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary S...

n/a PostgreSQL 18 CVE
LOW 3.5 CVE-2026-7471

Server-Side Request Forgery (SSRF) in GitLab_CVE-2026-7471

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 18.8 CVE
LOW 2.6 CVE-2026-6883

Missing Authorization in GitLab_CVE-2026-6883

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 15.7 CVE