Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2026-44278

CVE-2026-44278_CVE-2026-44278

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may all...

Fortinet FortiClientWindows 7.4.0 CVE
LOW 2.1 CVE-2026-43930

Parse Server: MFA SMS one-time password accepted twice under concurrent login_CVE-2026-43930

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race c...

parse-community parse-server >= 9.0.0, < 9.9.0-alpha.2 CVE
LOW 3.1 CVE-2026-40020

CVE-2026-40020_CVE-2026-40020

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes f...

Open-Xchange GmbH OX Dovecot Pro CVE
LOW 2.9 CVE-2026-32684

CVE-2026-32684_CVE-2026-32684

The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could o...

Hikvision Hik-Connect APP V6.10.x CVE
LOW 3.3 CVE-2026-41530

CVE-2026-41530_CVE-2026-41530

The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product...

Chitora soft Lhaz 2.6.3 and earlier CVE
LOW 3.4 CVE-2026-40131

SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library_CVE-2026-40131

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parame...

SAP_SE SAP HANA Deployment Infrastructure (HDI) deploy library XS_HDI_DEPLOYER 1.00 CVE
LOW 3.2 CVE-2026-45362

CVE-2026-45362_CVE-2026-45362

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Sangoma Switchvox CVE
LOW 2.4 CVE-2026-42188

Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL_CVE-2026-42188

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerabili...

GeyserMC Geyser < 2.9.3 CVE
LOW 2.3 CVE-2026-42865

Inbox Zero: Cross-account cleaner email stream exposure_CVE-2026-42865

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, whi...

elie222 inbox-zero < 2.29.3 CVE
LOW 2.1 CVE-2026-43969

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1_CVE-2026-43969

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling v...

ninenines cowlib 2.9.0 CVE