Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-33244

React Router has stored XSS via unescaped Location header in prerendered redirect HTML_CVE-2026-33244

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization...

remix-run react-router >= 7.5.1, < 7.13.2 CVE
MEDIUM 6.9 CVE-2026-10606

DedeCMS Feedback feedback.php TrimMsg sql injection_CVE-2026-10606

A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feed...

n/a DedeCMS 5.7.88 CVE
MEDIUM 6.5 CVE-2026-40564

Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator_CVE-2026-40564

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The Fli...

Apache Software Foundation Apache Flink Kubernetes Operator 1.3.0 CVE
MEDIUM 5.9 CVE-2026-0077

CVE-2026-0077_CVE-2026-0077

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. Th...

Google Android 16-qpr2 CVE
MEDIUM 5.9 CVE-2026-0075

CVE-2026-0075_CVE-2026-0075

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privi...

Google Android 16-qpr2 CVE
MEDIUM 5.9 CVE-2026-0061

CVE-2026-0061_CVE-2026-0061

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. ...

Google Android 16-qpr2 CVE
MEDIUM 6.2 CVE-2026-0009

CVE-2026-0009_CVE-2026-0009

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no ad...

Google Android 16 CVE
MEDIUM 5.9 CVE-2025-26418

CVE-2025-26418_CVE-2025-26418

In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a mana...

Google Android 15 CVE
MEDIUM 5.9 CVE-2025-22426

CVE-2025-22426_CVE-2025-22426

In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to ...

Google Android 16-qpr2 CVE
MEDIUM 6.1 CVE-2026-10510

GeniexWebView XSS in com.transsion.aiassistantlifestyle_CVE-2026-10510

Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all vers...

TECNO Mobile com.transsion.aiassistantlifestyle v1.3.0.002 CVE