Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-11623

tmux image.c image_free use after free_CVE-2026-11623

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to ...

n/a tmux 3.6a CVE
LOW 3.1 CVE-2026-11691

CVE-2026-11691_CVE-2026-11691

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11686

CVE-2026-11686_CVE-2026-11686

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised ...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11684

CVE-2026-11684_CVE-2026-11684

Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility proce...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11675

CVE-2026-11675_CVE-2026-11675

Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cros...

Google Chrome 149.0.7827.103 CVE
LOW 3.7 CVE-2026-44743

Security Misconfiguration vulnerability in SAP Business Objects_CVE-2026-44743

Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information ...

SAP_SE SAP Business Objects ENTERPRISE 430 CVE
LOW 2.1 CVE-2026-47344

TYPO3 HTML Sanitizer allows Cross-Site Scripting_CVE-2026-47344

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., ) are not recognized by the sanitizer but accepted by browsers as v...

TYPO3 HTML Sanitizer CVE
LOW 2.1 CVE-2026-49756

Multipart form-data header injection in Req via unescaped name/filename/content_type_CVE-2026-49756

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-infl...

wojtekmach req 0.5.3 CVE
LOW 2.7 CVE-2026-48488

phpMyFAQ has Weak Cryptography – SHA1 for Password Hashing_CVE-2026-48488

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken alg...

thorsten phpMyFAQ < 4.1.4 CVE
LOW 2.3 CVE-2026-11505

GL.iNet XE3000 glnassys hard-coded key_CVE-2026-11505

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the co...

GL.iNet A1300 4.8.* CVE