Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-40184

Unauthenticated Access to Uploaded Files in TREK_CVE-2026-40184

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed i...

mauriceboe TREK < 2.7.2 CVE
LOW 3.7 CVE-2026-40194

phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()_CVE-2026-40194

phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operat...

phpseclib phpseclib < 1.0.28 CVE
LOW 2.9 CVE-2026-40354

CVE-2026-40354_CVE-2026-40354

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack...

Flatpak xdg-desktop-portal CVE
LOW 2.3 CVE-2026-27484

OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows_CVE-2026-27484

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender ident...

openclaw openclaw < 2026.2.18 CVE
LOW 2 CVE-2026-27467

BigBlueButton: Audio from participants to the server initially unmuted_CVE-2026-27467

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client...

bigbluebutton bigbluebutton < 3.0.20 CVE
LOW 2.3 CVE-2026-27205

Flask session does not add `Vary: Cookie` header when accessed in some ways_CVE-2026-27205

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask s...

pallets flask < 3.1.3 CVE
LOW 3.7 CVE-2026-22885

EnOcean SmartServer IoT Out-of-bounds Read_CVE-2026-22885

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management me...

EnOcean Edge Inc SmartServer IoT CVE
LOW 3.5 CVE-2025-52603

HCL Connections is vulnerable to information disclosure_CVE-2025-52603

HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited in...

HCLSoftware Connections 7.0, 8.0 CVE
LOW 2.3 CVE-2025-14547

ECJ-PAKE Integer Underflow Vulnerability in Silicon Labs PSA Crypto and SE Manager APIs_CVE-2025-14547

An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Trigge...

silabs.com Simplicity SDK CVE
LOW 2.4 CVE-2025-14055

Integer underflow in Secure NCP host_CVE-2025-14055

An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a specially crafted packet.

silabs.com Simplicity SDK CVE