Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-10836

Improper neutralization of HTTP headers in Password Manager_CVE-2026-10836

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A succ...

Password Manager Password Manager CVE
MEDIUM 4.3 CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,_CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to o...

HCL Software ZIE 16.0 CVE
MEDIUM 6.5 CVE-2026-54817

WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability_CVE-2026-54817

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue...

FluxBuilder MStore API n/a CVE
MEDIUM 6.5 CVE-2026-52716

WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerability_CVE-2026-52716

Unauthenticated Arbitrary File Deletion in WorkScout-Core

purethemes WorkScout-Core n/a CVE
MEDIUM 5.3 CVE-2025-15657

WordPress School Management plugin <= 93.1.0 - Insecure Direct Object References (IDOR) vulnerability_CVE-2025-15657

Unauthenticated Insecure Direct Object References (IDOR) in School Management

Mojoomla School Management n/a CVE
MEDIUM 4.3 CVE-2026-12469

CVE-2026-12469_CVE-2026-12469

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.5 CVE-2026-12461

CVE-2026-12461_CVE-2026-12461

Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive informat...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.1 CVE-2026-12459

CVE-2026-12459_CVE-2026-12459

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12456

CVE-2026-12456_CVE-2026-12456

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12453

CVE-2026-12453_CVE-2026-12453

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rend...

Google Chrome 149.0.7827.155 CVE