Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-11109

CVE-2026-11109_CVE-2026-11109

Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Ch...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11107

CVE-2026-11107_CVE-2026-11107

Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HT...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11106

CVE-2026-11106_CVE-2026-11106

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTM...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11105

CVE-2026-11105_CVE-2026-11105

Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rende...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11104

CVE-2026-11104_CVE-2026-11104

Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain pot...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11101

CVE-2026-11101_CVE-2026-11101

Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11098

CVE-2026-11098_CVE-2026-11098

Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendere...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11097

CVE-2026-11097_CVE-2026-11097

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.4 CVE-2026-9281

Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension)_CVE-2026-9281

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cr...

litonice13 Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits CVE
MEDIUM 4.3 CVE-2026-9008

Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes_CVE-2026-9008

The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_un...

webvitaly Page-list CVE