Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.7 CVE-2026-20255

Improper Input Validation through Classic Dashboards in Splunk Enterprise_CVE-2026-20255

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2...

Splunk Splunk Enterprise 10.2 CVE
MEDIUM 5.7 CVE-2026-20254

Information Disclosure through External Content Restriction Bypass in Splunk Enterprise_CVE-2026-20254

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2...

Splunk Splunk Enterprise 10.2 CVE
MEDIUM 4.7 CVE-2026-11596

CVE-2026-11596_CVE-2026-11596

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host ...

ConnectWise ScreenConnect All versions prior to 26.2 CVE
MEDIUM 5.4 CVE-2026-11626

Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool_CVE-2026-11626

CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whe...

Broadcom Symantec Endpoint Protection CleanWipe Removal Tool 16.0.0.65 CVE
MEDIUM 5.3 CVE-2026-10740

Excessive memory allocation in s2n-quic_CVE-2026-10740

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of...

AWS s2n-quic CVE
MEDIUM 6.9 317E04B3-54AE-

Exploit for Incomplete Comparison with Missing Factors in Arista Eos_317E04B3-54AE-5CAF-87AE-5F2F7D5797F2

README.md markdown CVE-2026-7473 - Arista EOS Tunnel Decapsulation Bypass ⚠️ ADVERTENCIA Este código es SOLO para fines educativos y pruebas de seg...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-53442

CVE-2026-53442_CVE-2026-53442

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurati...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53440

CVE-2026-53440_CVE-2026-53440

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm ...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53439

CVE-2026-53439_CVE-2026-53439

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other use...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53438

CVE-2026-53438_CVE-2026-53438

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Rea...

Jenkins Project Jenkins 2.568 CVE