Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-47201

authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user_CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnera...

goauthentik authentik < 2025.12.5 CVE
HIGH 8.2 CVE-2026-8936

Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM_CVE-2026-8936

Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted h...

Docker Docker Desktop 4.33.0 CVE
HIGH 7 CVE-2025-15653

Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation_CVE-2025-15653

Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized i...

Dräger Zeus IE CVE
HIGH 7.5 40F8D208-F71D-

Exploit for Path Traversal in Grafana_40F8D208-F71D-51CF-9EFB-BEE62A4FBF14

CVE-2021-43798 - Grafana Arbitrary File Read Python toolkit for authorized testing of CVE-2021-43798, a Grafana path traversal vulnerability that c...

N/A N/A GITHUBEXPLOIT
HIGH 8.2 CVE-2026-10622

CVE-2026-10622_CVE-2026-10622

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/re...

Collibra Collibra Platform (on-prem) 2026.03 CVE
HIGH 7.5 CVE-2026-10621

CVE-2026-10621_CVE-2026-10621

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to...

Collibra Collibra Platform (SaaS) 2025.10 CVE
HIGH 8.4 CVE-2026-8036

Local privilege escalation in NI-PAL_CVE-2026-8036

Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escala...

NI NI-PAL CVE
HIGH 8.4 CVE-2026-5385

GLPI 11.0.0 – Stored XSS in knowledge base_CVE-2026-5385

An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: befor...

glpi-project glpi CVE
HIGH 7.5 CVE-2026-5073

ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter_CVE-2026-5073

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action...

armember ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup CVE
HIGH 8.2 CVE-2026-48597

Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint_CVE-2026-48597

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesl...

elixir-tesla tesla 1.3.0 CVE