Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-11272

CVE-2026-11272_CVE-2026-11272

Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-11265

CVE-2026-11265_CVE-2026-11265

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted ...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-46493

haxtheweb/haxcms-php uses insecure method for generating salt_CVE-2026-46493

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitabl...

haxtheweb haxcms-php < 26.0.1 CVE
HIGH 8.7 CVE-2026-46400

HAXCMS PHP has a File Upload Validation Bypass_CVE-2026-46400

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functi...

haxtheweb haxcms-php >= 11.0.6, < 25.0.0 CVE
HIGH 8.8 CVE-2026-46398

HAX CMS Missing Secure Flag on Cookie_CVE-2026-46398

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_tok...

haxtheweb haxcms-php >= 25.0.0, < 26.0.0 CVE
HIGH 8 CVE-2026-11401

Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL_CVE-2026-11401

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenti...

AWS AWS Advanced Go Wrapper 2026-04-06 CVE
HIGH 8 CVE-2026-11400

Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL_CVE-2026-11400

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authen...

AWS AWS Advanced JDBC Wrapper 3.0.0 CVE
HIGH 8.6 CVE-2026-45778

Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset_CVE-2026-45778

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious Ja...

ubccr xdmod < 11.0.3 CVE
HIGH 7.4 CVE-2026-45300

async-http-client: Cookie header not stripped on cross-origin redirect_CVE-2026-45300

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on t...

AsyncHttpClient async-http-client >= 3.0.0.Beta1, < 3.0.10 CVE
HIGH 7.1 CVE-2026-11422

Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering_CVE-2026-11422

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows...

shd101wyy Markdown Preview Enhanced CVE