Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-10923

CVE-2026-10923_CVE-2026-10923

Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malici...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11295

CVE-2026-11295_CVE-2026-11295

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalatio...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11272

CVE-2026-11272_CVE-2026-11272

Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-11265

CVE-2026-11265_CVE-2026-11265

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted ...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-46493

haxtheweb/haxcms-php uses insecure method for generating salt_CVE-2026-46493

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitabl...

haxtheweb haxcms-php < 26.0.1 CVE
HIGH 8.7 CVE-2026-46400

HAXCMS PHP has a File Upload Validation Bypass_CVE-2026-46400

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functi...

haxtheweb haxcms-php >= 11.0.6, < 25.0.0 CVE
HIGH 8.8 CVE-2026-46398

HAX CMS Missing Secure Flag on Cookie_CVE-2026-46398

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_tok...

haxtheweb haxcms-php >= 25.0.0, < 26.0.0 CVE
HIGH 8 CVE-2026-11401

Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL_CVE-2026-11401

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenti...

AWS AWS Advanced Go Wrapper 2026-04-06 CVE
HIGH 8 CVE-2026-11400

Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL_CVE-2026-11400

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authen...

AWS AWS Advanced JDBC Wrapper 3.0.0 CVE
HIGH 8.6 CVE-2026-45778

Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset_CVE-2026-45778

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious Ja...

ubccr xdmod < 11.0.3 CVE