< Back
Software Vulnerabilities
Last Updated On 14 Sep, 2026
- Parallels Desktop is vulnerable to a Local Privilege Escalation via Appliance Extract Argument InjectionCVE-2026-90894highDiscovered ByYuval MoravchickPublished on 14 Sep, 2026
- JFSA-2026-001686326Bifrost is vulnerable to Unauthenticated Remote Code Execution via MCP Stdio Client RegistrationCVE-2026-90898criticalDiscovered ByYuval MoravchickPublished on 14 Sep, 2026
- JFSA-2026-001684572Bifrost is vulnerable to Unauthenticated Remote Code Execution via a Custom Plugin HTTP Path on Dynamically Linked BuildsCVE-2026-86242highDiscovered ByOr PelesPublished on 6 Sep, 2026
- JFSA-2026-001683789Readest is vulnerable to Arbitrary Code Execution via Unsanitized iframe srcdoc in the EPUB SanitizerCVE-2026-82642highDiscovered ByYuval MoravchickPublished on 30 Aug, 2026
- JFSA-2026-001683788Pake is vulnerable to Arbitrary File Write via Unsanitized download_file FilenameCVE-2026-82635highDiscovered ByYuval MoravchickPublished on 30 Aug, 2026
- JFSA-2026-001683787The Reachy Mini Bluetooth command handler is vulnerable to Arbitrary Root Script Execution via Path TraversalCVE-2026-62661highDiscovered ByNatan NehoraiPublished on 25 Aug, 2026
- JFSA-2026-001667223Kimi Code is vulnerable to a FetchURL SSRF Protection Bypass via DNS-resolving Hostnames and RedirectsCVE-2026-17534mediumDiscovered ByNatan NehoraiPublished on 27 Jul, 2026
- JFSA-2026-001676778NoteGen is vulnerable to Arbitrary OS Command Execution via Tauri shell:allow-execute for bash/pythonCVE-2026-17497highDiscovered ByYuval MoravchickPublished on 26 Jul, 2026
- JFSA-2026-001676777NoteGen is vulnerable to Chat Preview XSS via Unsanitized AI/Skill HTML RenderingCVE-2026-17496highDiscovered ByYuval MoravchickPublished on 26 Jul, 2026
- JFSA-2026-001676838FFmpeg is vulnerable to a Heap Out-of-Bounds Write in the MagicYUV Decoder (PixelSmash)CVE-2026-8461highDiscovered ByOri HollanderPublished on 18 Jun, 2026