Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-45432

Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models_CVE-2026-45432

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface...

GX INDIA GX Earth 2022 version E2022 - 3.1.2A CVE
HIGH 8.7 CVE-2026-45431

Command Injection Vulnerability in GX Earth ONT Models_CVE-2026-45431

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web manage...

GX INDIA GX Earth 2022 version E2022 - 3.1.2A CVE
HIGH 7.2 CVE-2026-10843

Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws_CVE-2026-10843

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide ...

Red Hat Red Hat OpenShift Container Platform 4 CVE
HIGH 7.1 CVE-2025-52612

HCL iControl was affected by Export CSV – CSV Injection vulnerability._CVE-2025-52612

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was...

HCL iControl 4.0.0 CVE
HIGH 8.5 CVE-2025-12694

Local Privilege Escalation in VPN Client_CVE-2025-12694

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SY...

Forcepoint VPN Client CVE
HIGH 8.8 CVE-2026-50225

Account Creation Exhaustion_CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.6 CVE-2026-49771

WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability_CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL...

10Web Photo Gallery by 10Web n/a CVE
HIGH 8.7 CVE-2026-50213

Bulk User Private Data Harvesting_CVE-2026-50213

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ide...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.1 CVE-2026-50212

Arbitrary Remote Device Unbinding_CVE-2026-50212

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe ...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50211

Exposed Factory Testing App Boundaries_CVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to i...

Acer Connect M6E 5G Portable WiFi Router * CVE