Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2025-10268

Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal_CVE-2025-10268

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible ...

Unknown Printcart Web to Print Product Designer for WooCommerce CVE
MEDIUM 6.5 CVE-2026-57620

WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allow...

Tim Strifler Exclusive Addons Elementor n/a CVE
MEDIUM 5.4 CVE-2026-6658

Cross-site Scripting (XSS) in jupyter/nbconvert_CVE-2026-6658

A vulnerability in jupyter/nbconvert versions

jupyter jupyter/jupyter unspecified CVE
MEDIUM 5.8 CVE-2026-57473

CVE-2026-57473_CVE-2026-57473

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of ...

Reolink Home Hub CVE
MEDIUM 6.5 CVE-2026-1869

User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass_CVE-2026-1869

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Bu...

wpeverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder CVE
MEDIUM 5.5 MS:CVE-2026-4367

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing_MS:CVE-2026-4367

{“lastseen”:”2026-06-26T07:47:53″,”description”:””,”published”:”2026-06-25T08:03:...

N/A N/A MSCVE
MEDIUM 6.8 CVE-2026-13282

CVE-2026-13282_CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via ...

Google Chrome 149.0.7827.201 CVE
MEDIUM 4.7 CVE-2026-50745

CVE-2026-50745_CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not fol...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50744

CVE-2026-50744_CVE-2026-50744

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID ...

Revive Adserver CVE
MEDIUM 4.4 CVE-2026-50742

CVE-2026-50742_CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issu...

Revive Adserver CVE