Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-3652

ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter_CVE-2026-3652

The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX...

n/a ARforms CVE
HIGH 8.9 CVE-2026-12681

CVE-2026-12681_CVE-2026-12681

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advan...

Google go-attestation CVE
HIGH 8.7 CVE-2026-7574

Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use_CVE-2026-7574

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) val...

Anthropic Claude Desktop Cowork 1.1348.0 CVE
HIGH 7.2 CVE-2026-5818

MCU Firmware Update Authentication Bypass on Caliptra Core_CVE-2026-5818

Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Cor...

Caliptra Core Runtime Firmware 2.0.0 CVE
HIGH 8.8 CVE-2026-54639

Style Dictionary – Prototype Pollution in convertTokenData utility function_CVE-2026-54639

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to...

style-dictionary style-dictionary >= 4.3.0, < 5.4.4 CVE
HIGH 8.1 CVE-2026-39253

CVE-2026-39253_CVE-2026-39253

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Se...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-54513

jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)_CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
HIGH 8.1 CVE-2026-54512

jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation_CVE-2026-54512

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
HIGH 8.8 CVE-2026-41862

CVE-2026-41862_CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enfo...

Spring Spring Statemachine 4.0.0 CVE
HIGH 8.4 CVE-2026-56785

FlatPress – Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields_CVE-2026-56785

FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and ...

FlatPress FlatPress CVE