Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-6658

Cross-site Scripting (XSS) in jupyter/nbconvert_CVE-2026-6658

A vulnerability in jupyter/nbconvert versions

jupyter jupyter/jupyter unspecified CVE
MEDIUM 5.8 CVE-2026-57473

CVE-2026-57473_CVE-2026-57473

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of ...

Reolink Home Hub CVE
MEDIUM 6.5 CVE-2026-1869

User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass_CVE-2026-1869

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Bu...

wpeverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder CVE
MEDIUM 5.5 MS:CVE-2026-4367

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing_MS:CVE-2026-4367

{“lastseen”:”2026-06-26T07:47:53″,”description”:””,”published”:”2026-06-25T08:03:...

N/A N/A MSCVE
MEDIUM 6.8 CVE-2026-13282

CVE-2026-13282_CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via ...

Google Chrome 149.0.7827.201 CVE
MEDIUM 4.7 CVE-2026-50745

CVE-2026-50745_CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not fol...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50744

CVE-2026-50744_CVE-2026-50744

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID ...

Revive Adserver CVE
MEDIUM 4.4 CVE-2026-50742

CVE-2026-50742_CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issu...

Revive Adserver CVE
MEDIUM 6.1 CVE-2026-50740

CVE-2026-50740_CVE-2026-50740

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged use...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50739

CVE-2026-50739_CVE-2026-50739

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and tra...

Revive Adserver CVE