Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-5375

runZero Platform API credential information leak_CVE-2026-5375

An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instanc...

runZero Platform CVE
LOW 3 CVE-2026-5382

runZero Platform MCP endpoint information leak_CVE-2026-5382

An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of...

runZero Platform CVE
LOW 2.2 CVE-2026-5381

runZero Platform task information leak_CVE-2026-5381

An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorre...

runZero Platform CVE
LOW 3 CVE-2026-5379

runZero Platform MCP certification information leak_CVE-2026-5379

An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is a...

runZero Platform CVE
LOW 2.7 CVE-2026-4292

Privilege abuse in ModelAdmin.list_editable_CVE-2026-4292

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` inco...

djangoproject Django 6.0 CVE
LOW 2.1 CVE-2026-39349

OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure_CVE-2026-39349

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with ...

orangehrm orangehrm >= 5.0, < 5.8.1 CVE
LOW 2 CVE-2026-27949

Plane Exposes User Email (PII and part of credential) in GET Parameter_CVE-2026-27949

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's em...

makeplane plane < 1.3.0 CVE
LOW 2.8 CVE-2026-34781

Electron crashes in clipboard.readImage() on malformed clipboard image data_CVE-2026-34781

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0...

electron electron < 39.8.5 CVE
LOW 3.3 CVE-2026-28264

CVE-2026-28264_CVE-2026-28264

Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low...

Dell PowerProtect Agent CVE
LOW 2.3 CVE-2026-34720

Zammad has an origin validation error in SSO mechanism_CVE-2026-34720

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the hea...

zammad zammad < 6.5.4 CVE