Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-11071

CVE-2026-11071_CVE-2026-11071

Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtai...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11041

CVE-2026-11041_CVE-2026-11041

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromise...

Google Chrome 149.0.7827.53 CVE
HIGH 7.1 CVE-2026-11269

CVE-2026-11269_CVE-2026-11269

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute ...

Google Chrome 149.0.7827.53 CVE
HIGH 8.2 CVE-2026-45327

TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection_CVE-2026-45327

TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauth...

DatanoiseTV tinyice >= 0.8.95, < 2.5.0 CVE
HIGH 7.5 CVE-2026-45291

Cloudburst Network erroneously handles invalid connections_CVE-2026-45291

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32`...

CloudburstMC Network < 1.0.0.CR3-20260418.124334-32 CVE
HIGH 7.5 CVE-2026-45290

Cloudburst Network has DoS in RakNet connection handling due to missing bound checks_CVE-2026-45290

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30`...

CloudburstMC Network < 1.0.0.CR3-20260417.085727-30 CVE
HIGH 8.6 CVE-2026-50733

Markdown Preview Enhanced Arbitrary Code Execution via WaveDrom eval()_CVE-2026-50733

Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScrip...

shd101wyy Markdown Preview Enhanced CVE
HIGH 8.6 CVE-2026-49493

Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()_CVE-2026-49493

Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.run...

shd101wyy Markdown Preview Enhanced CVE
HIGH 8.6 CVE-2026-49492

Markdown Preview Enhanced OS Command Injection in External File and Link Opening_CVE-2026-49492

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs take...

shd101wyy Markdown Preview Enhanced CVE
HIGH 8.1 CVE-2026-45749

Termix’s TOTP two-factor authentication can be disabled or bypassed using only the account password_CVE-2026-45749

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `P...

Termix-SSH Termix < 2.3.2 CVE