cve-2026-55383 let public customer document tokens cross company boundaries in invoiceshelf through emaillog type confusion and missing expiry checks
bypassing java-side pairip checks in a modded android app by removing manifest-registered components, rebuilding, and signing again
cve-2026-54258 let low-privileged zoneminder users fetch private event media from monitors they were not allowed to access