Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-10984

CVE-2026-10984_CVE-2026-10984

Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing v...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6 CVE-2026-11326

CVE-2026-11326_CVE-2026-11326

OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in f...

OpenAI OpenAI Atlas CVE
MEDIUM 6.9 CVE-2026-11344

code-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload_CVE-2026-11344

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the compone...

code-projects Vehicle Management System 1.0 CVE
MEDIUM 6.9 CVE-2026-11342

code-projects Hotel and Tourism Reservation System details.php sql injection_CVE-2026-11342

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php...

code-projects Hotel and Tourism Reservation System 1.0 CVE
MEDIUM 5.3 CVE-2026-11341

D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection_CVE-2026-11341

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This mani...

D-Link DWR-M920 1.1.0 CVE
MEDIUM 5.9 CVE-2026-2379

Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled_CVE-2026-2379

On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in sp...

Arista Networks EOS 4.34.0 CVE
MEDIUM 6.9 CVE-2026-46390

HAX CMS has Unauthenticated Git Access via User-Controlled Key_CVE-2026-46390

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is e...

haxtheweb haxcms-php >= 2.0.0, < 26.0.0 CVE
MEDIUM 6.1 PACKETSTORM:222812

📄 Lyrion Music Server 9.2.0 search Cross Site Scripting_PACKETSTORM:222812

Lyrion Music Server version 9.2.0 has advanced search parameters that are stuffed back into the page so the form keeps its values. Several free-tex...

N/A N/A PACKETSTORM
MEDIUM 6.9 PACKETSTORM:222810

📄 Lyrion Music Server 9.2.0 Arbitrary Directory Listing_PACKETSTORM:222810

Lyrion Music Server version 9.2.0 exposes a readdirectory query through both its CLI service TCP port 9090 and its HTTP JSON-RPC endpoint /jsonrpc....

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:222802

📄 Lyrion Music Server 9.2.0 server.log Reflected Cross Site Scripting_PACKETSTORM:222802

Lyrion Music Server version 9.2.0 suffers from an unauthenticated reflected cross site scripting vulnerability through server.log endpoint abusing ...

N/A N/A PACKETSTORM