Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-34657

CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) (CWE-22)_CVE-2026-34657

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dire...

Adobe CAI Content Credentials CVE
MEDIUM 5.1 CVE-2026-34417

OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php_CVE-2026-34417

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim...

brian-ruf OSCAL-GUI CVE
MEDIUM 5.3 CVE-2026-25860

OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler_CVE-2026-25860

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute a...

frankverbeke OpenClinic GA CVE
MEDIUM 6.8 CVE-2026-9751

Sensitive data could be written to mongod.log_CVE-2026-9751

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

MongoDB MongoDB Server 8.3.0 CVE
MEDIUM 6.8 CVE-2026-9735

Keyfile contents are in MongoDB Server logs_CVE-2026-9735

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metri...

MongoDB MongoDB Server 8.3.0 CVE
MEDIUM 6.5 CVE-2026-46433

lldpd: Heap OOB Read in VLAN Decapsulation memmove_CVE-2026-46433

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from recei...

lldpd lldpd < 1.0.22 CVE
MEDIUM 4.8 CVE-2026-45446

Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes_CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated D...

OpenSSL OpenSSL 4.0.0 CVE
MEDIUM 6.2 CVE-2026-42771

Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()_CVE-2026-42771

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME messag...

OpenSSL OpenSSL 4.0.0 CVE
MEDIUM 5.3 CVE-2026-42769

Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate_CVE-2026-42769

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) messa...

OpenSSL OpenSSL 4.0.0 CVE
MEDIUM 5.9 CVE-2026-42767

NULL Pointer Dereference in CRMF EncryptedValue Decryption_CVE-2026-42767

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client applica...

OpenSSL OpenSSL 4.0.0 CVE