Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-11108

CVE-2026-11108_CVE-2026-11108

Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation vi...

Google Chrome 149.0.7827.53 CVE
HIGH 7.3 CVE-2026-11103

CVE-2026-11103_CVE-2026-11103

Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11102

CVE-2026-11102_CVE-2026-11102

Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code insid...

Google Chrome 149.0.7827.53 CVE
HIGH 7.4 CVE-2026-10973

CVE-2026-10973_CVE-2026-10973

Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chr...

Google Chrome 149.0.7827.53 CVE
HIGH 7.4 CVE-2026-10968

CVE-2026-10968_CVE-2026-10968

Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10966

CVE-2026-10966_CVE-2026-10966

Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vi...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10955

CVE-2026-10955_CVE-2026-10955

Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory ac...

Google Chrome 149.0.7827.53 CVE
HIGH 7.2 CVE-2026-8901

Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data_CVE-2026-8901

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site...

plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More CVE
HIGH 7.2 CVE-2026-8438

All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path_CVE-2026-8438

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and incl...

davidanderson All-In-One Security (AIOS) – Security and Firewall CVE
HIGH 7.2 CVE-2026-7537

MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter_CVE-2026-7537

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_se...

mdjm MDJM Event Management CVE