Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2025-43236

CVE-2025-43236_CVE-2025-43236

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 1...

Apple macOS CVE
LOW 1.7 CVE-2026-34743

XZ Utils: Buffer overflow in lzma_index_append()_CVE-2026-34743

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to de...

tukaani-project xz < 5.8.3 CVE
LOW 2 CVE-2026-5420

Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key_CVE-2026-5420

A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.j...

Shinrays Games Goods Triple App 1 CVE
LOW 2.7 CVE-2026-34762

Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber_CVE-2026-34762

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from...

ellanetworks core < 1.8.0 CVE
LOW 3.7 CVE-2026-35537

CVE-2026-35537_CVE-2026-35537

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arb...

Roundcube Webmail CVE
LOW 3.1 CVE-2026-35538

CVE-2026-35538_CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CS...

Roundcube Webmail CVE
LOW 2 CVE-2026-5473

NASA cFS Pickle pickle.load deserialization_CVE-2026-5473

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manip...

NASA cFS 7.0 CVE
LOW 2.1 CVE-2026-5476

NASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow_CVE-2026-5476

A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tb...

NASA cFS 7.0 CVE
LOW 3.7 CVE-2026-3184

Util-linux: util-linux: access control bypass due to improper hostname canonicalization_CVE-2026-3184

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the sup...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.7 CVE-2026-34947

Discourse: Staged user custom fields are exposed on public invite pages_CVE-2026-34947

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0...

discourse discourse >= 2026.1.0-latest, < 2026.1.3 CVE