Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-13426

Client4 fails to validate path parameters_CVE-2026-13426

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API r...

Mattermost github.com/mattermost/mattermost/server/public v0.0.0 CVE
HIGH 7.5 CVE-2026-13283

CVE-2026-13283_CVE-2026-13283

Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific...

Google Chrome 149.0.7827.201 CVE
HIGH 7.5 CVE-2026-10823

YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure_CVE-2026-10823

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supp...

Unknown YMC Filter CVE
MEDIUM 5.3 CVE-2025-10268

Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal_CVE-2025-10268

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible ...

Unknown Printcart Web to Print Product Designer for WooCommerce CVE
MEDIUM 6.5 CVE-2026-57620

WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allow...

Tim Strifler Exclusive Addons Elementor n/a CVE
HIGH 7.7 CVE-2026-57920

CVE-2026-57920_CVE-2026-57920

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Peplink InControl CVE
HIGH 8 CVE-2026-40711

CVE-2026-40711_CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) ...

Dell Container Storage Modules CVE
MEDIUM 5.4 CVE-2026-6658

Cross-site Scripting (XSS) in jupyter/nbconvert_CVE-2026-6658

A vulnerability in jupyter/nbconvert versions

jupyter jupyter/jupyter unspecified CVE
HIGH 7.1 CVE-2026-57918

CVE-2026-57918_CVE-2026-57918

libnfs through 6.0.2 before f0b109d has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a cra...

sahlberg libnfs CVE
HIGH 7.5 CVE-2026-57913

CVE-2026-57913_CVE-2026-57913

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

Johnson & Johnson Audit Tracking Management System CVE