Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7 CVE-2026-34123

Whitelist Validation Bypass in TP-Link Tapo C520WS_CVE-2026-34123

On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a ...

TP-Link Systems Inc. Tapo C520WS v2 CVE
HIGH 8.3 CVE-2026-11431

Path Traversal in Altium Projects Service Allows Arbitrary File Read_CVE-2026-11431

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated...

Altium Altium Enterprise Server CVE
HIGH 8.3 CVE-2026-11424

Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure_CVE-2026-11424

A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An auth...

Altium Altium Enterprise Server CVE
HIGH 8.1 CVE-2026-11416

MoviePilot Path Traversal via Cloud Storage Download Handlers_CVE-2026-11416

MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path...

jxxghp MoviePilot CVE
HIGH 8.8 CVE-2026-7654

Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value_CVE-2026-7654

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.1...

codepress Admin Columns CVE
HIGH 7.3 CVE-2026-11035

CVE-2026-11035_CVE-2026-11035

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escala...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11030

CVE-2026-11030_CVE-2026-11030

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious ne...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10951

CVE-2026-10951_CVE-2026-10951

Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI g...

Google Chrome 149.0.7827.53 CVE
HIGH 8.1 CVE-2026-10938

CVE-2026-10938_CVE-2026-10938

Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to...

Google Chrome 149.0.7827.53 CVE
HIGH 8.1 CVE-2026-10937

CVE-2026-10937_CVE-2026-10937

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a craf...

Google Chrome 149.0.7827.53 CVE