Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.6 CVE-2026-41974

CVE-2026-41974_CVE-2026-41974

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

Huawei HarmonyOS 4.3.1 CVE
LOW 3.7 CVE-2026-41852

Spring Framework Arbitrary Method Invocation in SpEL Expressions_CVE-2026-41852

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted ...

Spring Spring Framework 7.0.0 CVE
LOW 3.7 CVE-2026-41848

Spring Framework Denial of Service via AntPathMatcher_CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then d...

Spring Spring Framework 7.0.0 CVE
LOW 2 CVE-2026-11623

tmux image.c image_free use after free_CVE-2026-11623

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to ...

n/a tmux 3.6a CVE
LOW 3.1 CVE-2026-11691

CVE-2026-11691_CVE-2026-11691

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11686

CVE-2026-11686_CVE-2026-11686

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised ...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11684

CVE-2026-11684_CVE-2026-11684

Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility proce...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11675

CVE-2026-11675_CVE-2026-11675

Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cros...

Google Chrome 149.0.7827.103 CVE
LOW 3.7 CVE-2026-44743

Security Misconfiguration vulnerability in SAP Business Objects_CVE-2026-44743

Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information ...

SAP_SE SAP Business Objects ENTERPRISE 430 CVE
LOW 2.1 CVE-2026-47344

TYPO3 HTML Sanitizer allows Cross-Site Scripting_CVE-2026-47344

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., ) are not recognized by the sanitizer but accepted by browsers as v...

TYPO3 HTML Sanitizer CVE