Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-42183

Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)_CVE-2026-42183

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before versi...

argoproj argo-workflows >= 4.0.0, < 4.0.5 CVE
LOW 3.8 CVE-2026-44987

SysReptor: Privilege Escalation from User Admin to Superuser_CVE-2026-44987

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email ad...

Syslifters sysreptor < 2026.29 CVE
LOW 2.3 CVE-2026-44286

FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation_CVE-2026-44286

FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows atta...

labring FastGPT < 4.14.17 CVE
LOW 3.4 CVE-2026-42195

Unvalidated gitlab URL parameter redirects OAuth authorize step to attacker-controlled host_CVE-2026-42195

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter t...

jgraph drawio < 29.7.9 CVE
LOW 2.3 CVE-2026-42794

Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug_CVE-2026-42794

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scrip...

absinthe-graphql absinthe_plug 1.2.0 CVE
LOW 2.3 CVE-2026-41889

pgx: SQL Injection via placeholder confusion with dollar quoted string literals_CVE-2026-41889

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a doll...

jackc pgx < 5.9.2 CVE
LOW 3.3 CVE-2026-32803

CVE-2026-32803_CVE-2026-32803

Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains a...

Dell PowerScale OneFS CVE
LOW 3 CVE-2026-44916

CVE-2026-44916_CVE-2026-44916

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.

OpenStack Ironic CVE
LOW 2.9 CVE-2026-44928

CVE-2026-44928_CVE-2026-44928

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

uriparser uriparser CVE
LOW 2.9 CVE-2026-44927

CVE-2026-44927_CVE-2026-44927

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

uriparser uriparser CVE