Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.9 CVE-2026-33769

Astro: Remote allowlist bypass via unanchored matchPathname wildcard_CVE-2026-33769

Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URL...

withastro astro >= 2.10.10, < 5.18.1 CVE
LOW 2.1 CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests_CVE-2026-33624

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54...

parse-community parse-server < 8.6.60 CVE
LOW 1.9 CVE-2026-4433

CVE-2026-4433_CVE-2026-4433

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user...

Tenable, Inc. Tenable Operation Technology 3.18.58 CVE
LOW 3.3 CVE-2026-28893

CVE-2026-28893_CVE-2026-28893

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a te...

Apple macOS CVE
LOW 3.3 CVE-2026-28864

CVE-2026-28864_CVE-2026-28864

This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S...

Apple iOS and iPadOS CVE
LOW 3.3 CVE-2026-20684

CVE-2026-20684_CVE-2026-20684

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.

Apple macOS CVE
LOW 3.3 CVE-2026-4761

Unnecessary permissions on private keys of certificates installed by Network and Security Wizard_CVE-2026-4761

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the...

CODRA Panorama Suite Panorama Suite 2025 CVE
LOW 3.7 CVE-2026-4363

Incorrect Authorization in GitLab_CVE-2026-4363

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under...

GitLab GitLab 18.1 CVE
LOW 3.1 CVE-2025-14808

IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information_CVE-2025-14808

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTT...

IBM InfoSphere Information Server 11.7.0.0 CVE
LOW 2 CVE-2026-4823

Enter Software Iperius Backup NTLM2 information disclosure_CVE-2026-4823

A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTL...

Enter Software Iperius Backup 8.7.0 CVE