📋 ADVISORIES
-
📄 Source for Two vulnerabilities affect Reactor Netty HTTP servers — spring.io
-
📄 Source for OpenStack Keystone flaw exposes cloud-wide role assignments to readers — launchpad.net
🔓 CVEs & KEV
-
CVE-2026-65956 — CVSS 10.0 — KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover ...
-
CVE-2026-16639 — CVSS 9.8 — Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2...
-
CVE-2026-16641 — CVSS 9.8 — Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084Vulnerability i...
-
CVE-2026-16644 — CVSS 9.1 — Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087Incor...
-
CVE-2026-16645 — CVSS 9.1 — PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical ...
-
CVE-2026-47665 — CVSS 8.7 — Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTMLPen...
-
CVE-2026-47666 — CVSS 7.6 — Penpot: Stored XSS via custom font family name injected into a @font-face sty...
-
CVE-2026-18259 — CVSS 7.5 — Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-...
-
CVE-2026-47852 — CVSS 7.5 — Predictable cache directory location allows local ONNX model substitution in ...
-
CVE-2026-47851 — CVSS 7.5 — Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PD...
-
CVE-2026-47860 — CVSS 6.5 — Unbounded decompression of attacker-supplied compressed message bodiesAn atta...
-
CVE-2026-47861 — CVSS 6.3 — UDP adapter sends ack to attacker-supplied host:port parsed from packet body,...
-
CVE-2026-47856 — CVSS 6.3 — JsonToObjectTransformer resolves the json__TypeId__ message header to an arbi...
-
CVE-2026-16638 — CVSS 6.1 — Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-...
-
CVE-2026-16640 — CVSS 6.1 — Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CON...