CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-80191 HIGH

CVE-2026-80191 published: GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to ...

View full advisory →
CVE-2026-76149 MEDIUM

CVE-2026-76149 published: CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

View full advisory →
CVE-2026-76148 HIGH

CVE-2026-76148 published: CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.

View full advisory →
CVE-2026-73335 MEDIUM

CVE-2026-73335 published: Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, poten...

View full advisory →
CVE-2026-58089 HIGH

CVE-2026-58089 published: When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs ...

View full advisory →
CVE-2026-58090 HIGH

CVE-2026-58090 published: The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unp...

View full advisory →
CVE-2026-58091 HIGH

CVE-2026-58091 published: The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the...

View full advisory →
CVE-2026-58092 HIGH

CVE-2026-58092 published: In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a de...

View full advisory →
CVE-2026-54467 HIGH

CVE-2026-54467 published: On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

View full advisory →
CVE-2026-57170 HIGH

CVE-2026-57170 published: Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an...

View full advisory →
CVE-2026-57171 HIGH

CVE-2026-57171 published: Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated ...

View full advisory →
CVE-2026-52776 UNKNOWN

CVE-2026-52776 published: Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypa...

View full advisory →
CVE-2026-29988 HIGH

CVE-2026-29988 published: A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and Ap...

View full advisory →
CVE-2026-19632 CRITICAL

CVE-2026-19632 published: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible...

View full advisory →
CVE-2026-16643 MEDIUM

CVE-2026-16643 published: Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

View full advisory →
CVE-2026-16644 CRITICAL

CVE-2026-16644 published: Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

View full advisory →
CVE-2026-16645 CRITICAL

CVE-2026-16645 published: Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

View full advisory →
CVE-2026-16646 MEDIUM

CVE-2026-16646 published: Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

View full advisory →
CVE-2026-18259 HIGH

CVE-2026-18259 published: Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

View full advisory →
CVE-2026-18260 MEDIUM

CVE-2026-18260 published: Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.

View full advisory →