Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-2555

JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization_CVE-2026-2555

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/aira...

n/a JeecgBoot 3.9.1 CVE
LOW 3.8 CVE-2025-14573

Team Admin Bypass of Invite Permissions via allow_open_invite Field_CVE-2025-14573

Mattermost versions 10.11.x

Mattermost Mattermost 10.11.0 CVE
LOW 3.3 CVE-2026-20681

CVE-2026-20681_CVE-2026-20681

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be able to ...

Apple macOS unspecified CVE
LOW 3.3 CVE-2026-20646

CVE-2026-20646_CVE-2026-20646

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive ...

Apple macOS unspecified CVE
LOW 2.5 CVE-2026-0872

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon_CVE-2026-0872

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation...

Thales SafeNet Agent for Windows Logon 4.0.0 CVE
LOW 3.1 CVE-2026-20796

Time-of-check time-of-use vulnerability in common teams API_CVE-2026-20796

Mattermost versions 10.11.x

Mattermost Mattermost 10.11.0 CVE
LOW 2 CVE-2025-9292

Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers_CVE-2025-9292

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances...

TP-Link Systems Inc. Omada Cloud Controller CVE
LOW 3.3 CVE-2026-20663

CVE-2026-20663_CVE-2026-20663

The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to ...

Apple iOS and iPadOS unspecified CVE
LOW 2 CVE-2025-55210

FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes_CVE-2025-55210

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API)...

FreePBX api >= 15.0.1alpha1, < 16.0.17 CVE
LOW 3.1 CVE-2026-20671

CVE-2026-20671_CVE-2026-20671

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequ...

Apple macOS unspecified CVE