Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 3A0FB196-510A-

Exploit for Improper Initialization in Linux Linux_Kernel_3A0FB196-510A-59F0-AD4E-7E47BB4CD069

CVE-2022-0847 Dirty Pipe Pre-compiled exploit for CVE-2022-0847 Dirty Pipe. Original source code from haxx.in/dirtypipe. Build bash make glibc stat...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-9290

WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter_CVE-2026-9290

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...

wpusermanager WP User Manager – User Profile Builder & Membership CVE
HIGH 7 CVE-2026-34123

Whitelist Validation Bypass in TP-Link Tapo C520WS_CVE-2026-34123

On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a ...

TP-Link Systems Inc. Tapo C520WS v2 CVE
HIGH 8.3 CVE-2026-11431

Path Traversal in Altium Projects Service Allows Arbitrary File Read_CVE-2026-11431

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated...

Altium Altium Enterprise Server CVE
HIGH 8.3 CVE-2026-11424

Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure_CVE-2026-11424

A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An auth...

Altium Altium Enterprise Server CVE
HIGH 8.1 CVE-2026-11416

MoviePilot Path Traversal via Cloud Storage Download Handlers_CVE-2026-11416

MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path...

jxxghp MoviePilot CVE
HIGH 8.8 CVE-2026-7654

Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value_CVE-2026-7654

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.1...

codepress Admin Columns CVE
HIGH 7.3 CVE-2026-11035

CVE-2026-11035_CVE-2026-11035

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escala...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11030

CVE-2026-11030_CVE-2026-11030

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious ne...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10951

CVE-2026-10951_CVE-2026-10951

Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI g...

Google Chrome 149.0.7827.53 CVE