Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.8 CVE-2026-6242

Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS_CVE-2026-6242

An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplie...

TP-Link Systems Inc. Tapo C520WS v2 CVE
MEDIUM 6.8 CVE-2026-6241

Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS_CVE-2026-6241

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed ...

TP-Link Systems Inc. Tapo C520WS v2 CVE
MEDIUM 6.8 CVE-2026-6240

Authenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WS_CVE-2026-6240

A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when han...

TP-Link Systems Inc. Tapo C520WS v2 CVE
MEDIUM 6.8 CVE-2026-6239

Authenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WS_CVE-2026-6239

A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device fails to properly validate ...

TP-Link Systems Inc. Tapo C520WS v2 CVE
MEDIUM 6.9 CVE-2026-45409

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix_CVE-2026-45409

Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Uni...

kjd idna < 3.15 CVE
MEDIUM 4.3 CVE-2026-7523

Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter_CVE-2026-7523

The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin no...

alejo30 Alba Board CVE
MEDIUM 6.5 CVE-2026-11057

CVE-2026-11057_CVE-2026-11057

Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain pote...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11051

CVE-2026-11051_CVE-2026-11051

Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11048

CVE-2026-11048_CVE-2026-11048

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11045

CVE-2026-11045_CVE-2026-11045

Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendere...

Google Chrome 149.0.7827.53 CVE