Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-10740

Excessive memory allocation in s2n-quic_CVE-2026-10740

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of...

AWS s2n-quic CVE
MEDIUM 6.9 317E04B3-54AE-

Exploit for Incomplete Comparison with Missing Factors in Arista Eos_317E04B3-54AE-5CAF-87AE-5F2F7D5797F2

README.md markdown CVE-2026-7473 - Arista EOS Tunnel Decapsulation Bypass ⚠️ ADVERTENCIA Este código es SOLO para fines educativos y pruebas de seg...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-53442

CVE-2026-53442_CVE-2026-53442

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurati...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53440

CVE-2026-53440_CVE-2026-53440

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm ...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53439

CVE-2026-53439_CVE-2026-53439

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other use...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53438

CVE-2026-53438_CVE-2026-53438

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Rea...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53437

CVE-2026-53437_CVE-2026-53437

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when i...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 4.3 CVE-2026-53436

CVE-2026-53436_CVE-2026-53436

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when i...

Jenkins Project Jenkins 2.568 CVE
MEDIUM 6.5 CVE-2026-53698

CVE-2026-53698_CVE-2026-53698

Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

Silverpeas Silverpeas CVE
MEDIUM 6.9 CVE-2026-53693

MISP BSimVis stored cross-site scripting in tag and cluster rendering paths via unescaped tag metadata and UI labels_CVE-2026-53693

A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names,...

misp bsimvis CVE