Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-11834

Unauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link Routers_CVE-2026-11834

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient va...

TP-Link Systems Inc. Archer MR200 v07 CVE
HIGH 7.8 CVE-2026-44274

CVE-2026-44274_CVE-2026-44274

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privilege...

Dell Wyse Management Suite (WMS) CVE
HIGH 8.8 CVE-2026-44272

CVE-2026-44272_CVE-2026-44272

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL I...

Dell Wyse Management Suite (WMS) CVE
HIGH 8.1 CVE-2026-44271

CVE-2026-44271_CVE-2026-44271

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL I...

Dell Wyse Management Suite (WMS) CVE
HIGH 7.5 MS:CVE-2026-12462

Chromium: CVE-2026-12462 Use after free in Media_MS:CVE-2026-12462

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-12454

Chromium: CVE-2026-12454 Race in Safe Browsing_MS:CVE-2026-12454

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.1 CVE-2025-66336

Apache Doris MCP Server: SQL injection leading the authentication bypass_CVE-2025-66336

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated i...

Apache Software Foundation Apache Doris MCP Server 0.1.0 CVE
HIGH 7.5 CVE-2025-66389

CVE-2025-66389_CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_web...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-10845

IBM WebSphere Application Server is affected by an authentication bypass vulnerability_CVE-2026-10845

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicat...

IBM WebSphere Application Server 8.5.0 CVE
HIGH 7 CVE-2026-56109

ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c_CVE-2026-56109

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows ...

alsa-project alsa-lib CVE