Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 CVE-2026-49777

WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability_CVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software ...

ShapedPlugin, LLC Product Slider Pro for WooCommerce n/a CVE
HIGH 7.8 CVE-2026-11332

Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution_CVE-2026-11332

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml f...

Red Hat Red Hat Ansible Automation Platform 2 CVE
LOW 2.7 CVE-2026-9088

Keycloak: keycloak: information disclosure due to user profile permission bypass_CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permi...

Red Hat Red Hat Build of Keycloak CVE
CRITICAL 10 CVE-2026-48907

Joomla Extension – joomlacontenteditor.net – Remote Code Execution in JCE extension for Joomla < 2.9.99.5_CVE-2026-48907

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting i...

joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.4 CVE
HIGH 7.8 CVE-2026-45956

drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()_CVE-2026-45956

In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()...

Linux Linux cf67cc9a29ac19c98bc4fa0e6d14b0c1f592d322 CVE
HIGH 7.1 CVE-2026-45955

md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout_CVE-2026-45955

In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitm...

Linux Linux 5ab829f1971dc99f2aac10846c378e67fc875abc CVE
HIGH 7.8 CVE-2026-46242

eventpoll: fix ep_remove struct eventpoll / struct file UAF_CVE-2026-46242

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ...

Linux Linux 58c9b016e12855286370dfb704c08498edbc857a CVE
HIGH 8.6 CVE-2026-46273

ibmveth: Disable GSO for packets with small MSS_CVE-2026-46273

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Pow...

Linux Linux 8641dd85799f85bef5f0d1f87356aaa12cb2195e CVE
HIGH 7.8 CVE-2026-46271

wifi: ath12k: do WoW offloads only on primary link_CVE-2026-46271

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi-link conn...

Linux Linux 32f7b19668bd2894f1a236580c2132fc4b9f4449 CVE
HIGH 8.4 CVE-2026-46270

power: supply: rt9455: Fix use-after-free in power_supply_changed()_CVE-2026-46270

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the...

Linux Linux e86d69dd786e94046b8f5be7df1b9a8226a40b2a CVE