Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-26241

File Station 5_CVE-2026-26241

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memor...

QNAP Systems Inc. File Station 5 5.5.0 CVE
MEDIUM 5.3 CVE-2026-26240

File Station 5_CVE-2026-26240

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memor...

QNAP Systems Inc. File Station 5 5.5.0 CVE
MEDIUM 6.4 CVE-2025-8444

Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates <= 2.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters_CVE-2025-8444

The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross...

wealcoder Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates CVE
MEDIUM 4.6 CVE-2026-46532

ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser_CVE-2026-46532

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exi...

espressif esp-idf = 5.2.6 CVE
MEDIUM 6.5 CVE-2026-45160

ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser_CVE-2026-45160

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read f...

espressif esp-idf = 5.2.7 CVE
MEDIUM 5.1 CVE-2025-59382

QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)_CVE-2025-59382

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

QNAP Systems Inc. QTS ? CVE
MEDIUM 5.1 CVE-2025-58468

Notification Center_CVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulner...

QNAP Systems Inc. Notification Center 1.10.0 CVE
MEDIUM 6.5 CVE-2026-46411

FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older_CVE-2026-46411

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the pe...

halfgaar FlashMQ < 1.26.2 CVE
MEDIUM 5.3 CVE-2026-53675

BuddyPress 14.4.0 Friends List IDOR via REST API_CVE-2026-53675

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enum...

BuddyPress BuddyPress CVE
MEDIUM 6.8 CVE-2026-47838

Unauthorized User Impersonation when Using X.509 Client Certificates_CVE-2026-47838

SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value ...

Spring Spring Security 5.7.0 CVE