Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-10011

CVE-2026-10011_CVE-2026-10011

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to...

Google Chrome 148.0.7778.216 CVE
LOW 3.3 CVE-2026-49383

CVE-2026-49383_CVE-2026-49383

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

JetBrains IntelliJ IDEA CVE
LOW 3.4 CVE-2026-49381

CVE-2026-49381_CVE-2026-49381

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

JetBrains TeamCity CVE
LOW 3.1 CVE-2026-49380

CVE-2026-49380_CVE-2026-49380

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

JetBrains TeamCity CVE
LOW 3.4 CVE-2026-49370

CVE-2026-49370_CVE-2026-49370

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

JetBrains YouTrack CVE
LOW 2.3 CVE-2026-34507

OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks_CVE-2026-34507

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allo...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-33386

XSS in QuickCMS_CVE-2026-33386

QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a ...

OpenSolution QuickCMS CVE
LOW 2.3 CVE-2026-32906

OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate_CVE-2026-32906

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plug...

OpenClaw OpenClaw CVE
LOW 2.4 CVE-2026-49318

Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot_CVE-2026-49318

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacen...

Indian Motorcycle (Polaris Inc.) Scout Bobber + Tech 2025 CVE
LOW 2.4 CVE-2026-49317

Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot_CVE-2026-49317

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacen...

Indian Motorcycle (Polaris Inc.) Scout Bobber + Tech 2025 CVE