Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-8607

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute_CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cro...

saadiqbal Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred CVE
MEDIUM 6.4 CVE-2026-8494

Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title_CVE-2026-8494

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in a...

mbis Permalink Manager Lite CVE
CRITICAL 10 CVE-2026-28615

CVE-2026-28615_CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of pri...

Google Android 17 CVE
CRITICAL 10 CVE-2026-28587

CVE-2026-28587_CVE-2026-28587

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could l...

Google Android 17 CVE
CRITICAL 10 CVE-2026-28576

CVE-2026-28576_CVE-2026-28576

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure...

Android Android 17 CVE
CRITICAL 10 CVE-2026-28575

CVE-2026-28575_CVE-2026-28575

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible ...

Google Android 17 CVE
HIGH 7.5 CVE-2026-12199

Unauthenticated Denial of Service in nltk.app.wordnet_app_CVE-2026-12199

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when ...

nltk nltk/nltk unspecified CVE
CRITICAL 9.8 CVE-2026-10094

Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026_CVE-2026-10094

A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could al...

Dassault Systèmes SOLIDWORKS Visualize SOLIDWORKS Desktop Release 2024 SP0 CVE
CRITICAL 10 CVE-2026-0092

CVE-2026-0092_CVE-2026-0092

In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of pri...

Google Android 17 CVE
CRITICAL 10 CVE-2026-0083

CVE-2026-0083_CVE-2026-0083

In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with...

Google Android 17 CVE