Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2026-50593

CVE-2026-50593_CVE-2026-50593

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offs...

Graphite project Graphite CVE
HIGH 8.1 CVE-2026-36603

CVE-2026-36603_CVE-2026-36603

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including Ad...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-36602

CVE-2026-36602_CVE-2026-36602

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticate...

n/a n/a n/a CVE
MEDIUM 4.1 CVE-2026-37700

CVE-2026-37700_CVE-2026-37700

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload...

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-11235

CVE-2026-11235_CVE-2026-11235

Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer p...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11230

CVE-2026-11230_CVE-2026-11230

Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11173

CVE-2026-11173_CVE-2026-11173

Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arb...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11171

CVE-2026-11171_CVE-2026-11171

Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11164

CVE-2026-11164_CVE-2026-11164

Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted ...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-11149

CVE-2026-11149_CVE-2026-11149

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ...

Google Chrome 149.0.7827.53 CVE