Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-10850

Plane 1.3.1 – Stored XSS in intake issue description_html_CVE-2026-10850

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item t...

Plane Plane 1.3.1 CVE
HIGH 8.1 CVE-2026-12290

Memory safety bug fixed in Thunderbird 152_CVE-2026-12290

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, a...

Mozilla Firefox 115.37 CVE
CRITICAL 9.1 CVE-2026-50203

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names_CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP se...

Apache Software Foundation Apache Airflow SFTP provider CVE
HIGH 8.3 CVE-2026-12468

CVE-2026-12468_CVE-2026-12468

Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially p...

Google Chrome 149.0.7827.155 CVE
HIGH 8.3 CVE-2026-12467

CVE-2026-12467_CVE-2026-12467

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potenti...

Google Chrome 149.0.7827.155 CVE
HIGH 8.8 CVE-2026-12466

CVE-2026-12466_CVE-2026-12466

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafte...

Google Chrome 149.0.7827.155 CVE
HIGH 8.3 CVE-2026-12465

CVE-2026-12465_CVE-2026-12465

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to po...

Google Chrome 149.0.7827.155 CVE
HIGH 8.3 CVE-2026-12464

CVE-2026-12464_CVE-2026-12464

Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentiall...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.7 CVE-2026-12463

CVE-2026-12463_CVE-2026-12463

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer ...

Google Chrome 149.0.7827.155 CVE
HIGH 7.5 CVE-2026-12462

CVE-2026-12462_CVE-2026-12462

Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbi...

Google Chrome 149.0.7827.155 CVE