CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-80191 published: GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to ...
View full advisory →CVE-2026-76149 published: CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
View full advisory →CVE-2026-76148 published: CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
View full advisory →CVE-2026-73335 published: Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, poten...
View full advisory →CVE-2026-58089 published: When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs ...
View full advisory →CVE-2026-58090 published: The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unp...
View full advisory →CVE-2026-58091 published: The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the...
View full advisory →CVE-2026-58092 published: In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a de...
View full advisory →CVE-2026-54467 published: On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
View full advisory →CVE-2026-57170 published: Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an...
View full advisory →CVE-2026-57171 published: Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated ...
View full advisory →CVE-2026-52776 published: Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypa...
View full advisory →CVE-2026-29988 published: A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and Ap...
View full advisory →CVE-2026-19632 published: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible...
View full advisory →CVE-2026-16643 published: Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
View full advisory →CVE-2026-16644 published: Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
View full advisory →CVE-2026-16645 published: Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
View full advisory →CVE-2026-16646 published: Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
View full advisory →CVE-2026-18259 published: Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.
View full advisory →CVE-2026-18260 published: Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
View full advisory →