Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-42766

Possible NULL Dereference in Password-Based CMS Decryption_CVE-2026-42766

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: Th...

OpenSSL OpenSSL 4.0.0 CVE
MEDIUM 5.7 CVE-2026-40639

CVE-2026-40639_CVE-2026-40639

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially e...

Dell Dell Edge Gateway 3000 CVE
MEDIUM 6.3 CVE-2026-39170

CVE-2026-39170_CVE-2026-39170

SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-36728

CVE-2026-36728_CVE-2026-36728

A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbi...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-36725

CVE-2026-36725_CVE-2026-36725

A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute ...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-36724

CVE-2026-36724_CVE-2026-36724

An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:u...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-36720

CVE-2026-36720_CVE-2026-36720

Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2025-55659

CVE-2025-55659_CVE-2025-55659

A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Serv...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2026-47910

Dreamweaver Desktop | Incorrect Authorization (CWE-863)_CVE-2026-47910

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system rea...

Adobe Dreamweaver Desktop CVE
MEDIUM 6.3 CVE-2026-47909

Dreamweaver Desktop | Improper Input Validation (CWE-20)_CVE-2026-47909

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system r...

Adobe Dreamweaver Desktop CVE