Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-53950

@tryghost/activitypub: XSS in Ghost’s ActivityPub client_CVE-2026-53950

@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injecti...

TryGhost Ghost < 3.1.0 CVE
HIGH 8.8 CVE-2026-49247

Jellyfin: Potential Authenticated path traversal in /ClientLog/Document_CVE-2026-49247

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization he...

jellyfin jellyfin >= 10.9.0, < 10.11.10 CVE
HIGH 8.8 CVE-2026-48793

Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path_CVE-2026-48793

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle ...

jellyfin jellyfin < 10.11.10 CVE
HIGH 7.1 CVE-2026-12760

Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200_CVE-2026-12760

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 f...

TP-Link Systems Inc. Tapo C200 v3 CVE
HIGH 8.8 CVE-2026-13038

CVE-2026-13038_CVE-2026-13038

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HT...

Google Chrome 149.0.7827.197 CVE
HIGH 7.8 CVE-2026-13037

CVE-2026-13037_CVE-2026-13037

Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox v...

Google Chrome 149.0.7827.197 CVE
HIGH 8.8 CVE-2026-13036

CVE-2026-13036_CVE-2026-13036

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Google Chrome 149.0.7827.197 CVE
HIGH 8.8 CVE-2026-13035

CVE-2026-13035_CVE-2026-13035

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious per...

Google Chrome 149.0.7827.197 CVE
HIGH 8.8 CVE-2026-13033

CVE-2026-13033_CVE-2026-13033

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code v...

Google Chrome 149.0.7827.197 CVE
HIGH 8.8 CVE-2026-13031

CVE-2026-13031_CVE-2026-13031

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Google Chrome 149.0.7827.197 CVE