Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-21027

CVE-2026-21027_CVE-2026-21027

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

Samsung Mobile Samsung Mobile Devices SMR Jun-2026 Release in Android 14, 15, 16 CVE
MEDIUM 6.4 CVE-2026-21026

CVE-2026-21026_CVE-2026-21026

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive ...

Samsung Mobile Samsung Mobile Devices SMR Jun-2026 Release in Android 16 CVE
MEDIUM 6.9 CVE-2026-21025

CVE-2026-21025_CVE-2026-21025

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

Samsung Mobile Samsung Mobile Devices SMR Jun-2026 Release in Android 14, 15, 16 CVE
MEDIUM 4.6 CVE-2026-21017

CVE-2026-21017_CVE-2026-21017

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged fi...

Samsung Mobile Samsung Mobile Devices SMR Jun-2026 Release in Android 14, 15, 16 CVE
MEDIUM 6.1 CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection_CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host heade...

HCLSoftware Digital Experience & DX Compose 9.5 CVE
MEDIUM 6.1 CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center_CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute...

HCLSoftware DX Compose 9.5 CVE
MEDIUM 6.4 CVE-2026-10732

CVE-2026-10732_CVE-2026-10732

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive conta...

n/a decompress CVE
MEDIUM 4.3 CVE-2026-36602

CVE-2026-36602_CVE-2026-36602

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticate...

n/a n/a n/a CVE
MEDIUM 4.1 CVE-2026-37700

CVE-2026-37700_CVE-2026-37700

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload...

n/a n/a n/a CVE
MEDIUM 5.1 CVE-2026-11276

CVE-2026-11276_CVE-2026-11276

Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretiona...

Google Chrome 149.0.7827.53 CVE