Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-46391

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis_CVE-2026-46391

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis,...

haxtheweb @haxtheweb/open-apis >= 9.0.1, < 26.0.0 CVE
MEDIUM 6.9 CVE-2026-46390

HAX CMS has Unauthenticated Git Access via User-Controlled Key_CVE-2026-46390

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is e...

haxtheweb haxcms-php >= 2.0.0, < 26.0.0 CVE
CRITICAL 10 CVE-2026-46389

UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`_CVE-2026-46389

UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. I...

defenseunicorns uds-identity-config >= 0.11.0, < 0.26.1 CVE
CRITICAL 9.8 CVE-2026-10580

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API_CVE-2026-10580

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all ...

hippooo Hippoo Mobile App for WooCommerce CVE
MEDIUM 6.5 CVE-2026-11208

CVE-2026-11208_CVE-2026-11208

Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11206

CVE-2026-11206_CVE-2026-11206

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.1 CVE-2026-11205

CVE-2026-11205_CVE-2026-11205

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11204

CVE-2026-11204_CVE-2026-11204

Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions v...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11203

CVE-2026-11203_CVE-2026-11203

Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafte...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11202

CVE-2026-11202_CVE-2026-11202

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sa...

Google Chrome 149.0.7827.53 CVE