Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-10843

Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws_CVE-2026-10843

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide ...

Red Hat Red Hat OpenShift Container Platform 4 CVE
HIGH 7.1 CVE-2025-52612

HCL iControl was affected by Export CSV – CSV Injection vulnerability._CVE-2025-52612

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was...

HCL iControl 4.0.0 CVE
HIGH 8.5 CVE-2025-12694

Local Privilege Escalation in VPN Client_CVE-2025-12694

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SY...

Forcepoint VPN Client CVE
HIGH 8.8 CVE-2026-50225

Account Creation Exhaustion_CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.6 CVE-2026-49771

WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability_CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL...

10Web Photo Gallery by 10Web n/a CVE
HIGH 8.7 CVE-2026-50213

Bulk User Private Data Harvesting_CVE-2026-50213

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ide...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.1 CVE-2026-50212

Arbitrary Remote Device Unbinding_CVE-2026-50212

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe ...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50211

Exposed Factory Testing App Boundaries_CVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to i...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.5 CVE-2026-50207

Local Modem Manipulation via Binder Interfaces_CVE-2026-50207

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellu...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.2 CVE-2026-3820

Supermicro BMC’s SMTP service contains a command injection vulnerability_CVE-2026-3820

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inje...

SMCI AS-2115HS-TNR 01.08.01 CVE