Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2026-26059

ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php_CVE-2026-26059

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit...

ChurchCRM CRM < 6.8.1 CVE
LOW 2.1 CVE-2026-26345

SPIP < 4.4.8 Cross-Site Scripting in Public Area_CVE-2026-26345

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function d...

SPIP SPIP 4.4.0 CVE
LOW 3.8 CVE-2026-2733

Org.keycloak/keycloak-services: keycloak: missing check on disabled client for docker registry protocol_CVE-2026-2733

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client ...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.3 CVE-2026-2702

Beetel 777VR1 WPA2 PSK hard-coded credentials_CVE-2026-2702

A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performi...

Beetel 777VR1 01.00.09 CVE
LOW 2.7 CVE-2025-14270

OneClick Chat to Order <= 1.0.9 - Missing Authorization to Authenticated (Editor+) Plugin Settings Update_CVE-2025-14270

The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the p...

walterpinem OneClick Chat to Order * CVE
LOW 3.7 CVE-2026-24764

OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions_CVE-2026-24764

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration ...

clawdbot clawdbot < 2026.2.3 CVE
LOW 3.3 CVE-2025-12343

Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend_CVE-2025-12343

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf()...

N/A N/A 6.1 CVE
LOW 3.3 CVE-2025-8860

Qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback_CVE-2025-8860

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_va...

N/A N/A 10.0.0 CVE
LOW 3.5 CVE-2026-20137

Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk Enterprise_CVE-2026-20137

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3...

Splunk Splunk Enterprise 10.2 CVE
LOW 3.3 CVE-2026-20656

CVE-2026-20656_CVE-2026-20656

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, Safari 26.3, macOS Tahoe 26.3. An app ma...

Apple Safari unspecified CVE