Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-49241

Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension_CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular L...

angular angular < 21.2.4 CVE
HIGH 8.4 CVE-2026-41049

Caching of Authentication allows Authentication Bypass between users in qSnapper_CVE-2026-41049

Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use db...

presire qSnapper 1.2.1 CVE
HIGH 8.4 CVE-2026-41048

Caching of Authentication allows Authentication Bypass in qSnapper_CVE-2026-41048

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions lik...

presire qSnapper 1.2.1 CVE
HIGH 7.3 CVE-2026-41046

path traversal via `config` parameter in qSnapper_CVE-2026-41046

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files...

presire qSnapper CVE
HIGH 8.1 CVE-2026-41045

Weak polkit authentication check in qSnapper_CVE-2026-41045

A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication m...

presire qSnapper CVE
HIGH 8.1 CVE-2026-12628

Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system_CVE-2026-12628

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attack...

IBM Storage Protect Client 8.1.0.0 CVE
HIGH 8.3 MS:CVE-2026-12468

Chromium: CVE-2026-12468 Inappropriate implementation in Updater_MS:CVE-2026-12468

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-12466

Chromium: CVE-2026-12466 Heap buffer overflow in WebRTC_MS:CVE-2026-12466

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 CVE-2026-8157

Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation_CVE-2026-8157

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST AP...

Unknown Vitepos CVE
HIGH 7.1 CVE-2026-6858

Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS_CVE-2026-6858

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform St...

Unknown Transbank Webpay CVE