Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-48652

CVE-2025-48652_CVE-2025-48652

In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead ...

Google Android 16-qpr2 CVE
HIGH 7.8 CVE-2025-48649

CVE-2025-48649_CVE-2025-48649

In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local ...

Google Android 16-qpr2 CVE
HIGH 7.8 CVE-2025-48570

CVE-2025-48570_CVE-2025-48570

In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This co...

Google Android 14 CVE
HIGH 7.8 CVE-2025-32348

CVE-2025-32348_CVE-2025-32348

In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of pri...

Google Android 16-qpr2 CVE
HIGH 7.5 CVE-2026-42670

WordPress Five Star Restaurant Reservations plugin <= 2.7.14 - Payment Bypass vulnerability_CVE-2026-42670

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Ac...

Etoile Web Design Incorporated Five Star Restaurant Reservations n/a CVE
HIGH 8.8 CVE-2026-9844

Vulnerability in navify Digital Pathology_CVE-2026-9844

Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usern...

Roche Diagnostics navify Digital Pathology 2.0.0 CVE
HIGH 8.7 CVE-2026-7313

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity_CVE-2026-7313

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticat...

Progress Software Sitefinity 8.0.5700 to 13.3.7652 CVE
HIGH 8.8 CVE-2026-7201

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity_CVE-2026-7201

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, ...

Progress Software Sitefinity 15.2.8400 CVE
HIGH 8.8 CVE-2026-7195

CWE-20: Improper Input Validation in web services in Progress Sitefinity_CVE-2026-7195

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 1...

Progress Software Sitefinity 14.1.0 CVE
HIGH 8.1 CVE-2026-39555

WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability_CVE-2026-39555

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

Elated-Themes Askka n/a CVE