Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-12528

389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()_CVE-2026-12528

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) str...

Red Hat Red Hat Directory Server 11 CVE
MEDIUM 6.9 CVE-2026-10850

Plane 1.3.1 – Stored XSS in intake issue description_html_CVE-2026-10850

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item t...

Plane Plane 1.3.1 CVE
MEDIUM 4.7 CVE-2026-12463

CVE-2026-12463_CVE-2026-12463

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer ...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12460

CVE-2026-12460_CVE-2026-12460

Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the re...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12457

CVE-2026-12457_CVE-2026-12457

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer proc...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.2 CVE-2026-11975

Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface_CVE-2026-11975

Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execu...

simplcommerce SimplCommerce CVE
MEDIUM 5.1 CVE-2026-10839

Open redirection vulnerability in Password Manager_CVE-2026-10839

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter th...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10837

Open redirection vulnerability in Password Manager_CVE-2026-10837

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that,...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10836

Improper neutralization of HTTP headers in Password Manager_CVE-2026-10836

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A succ...

Password Manager Password Manager CVE
MEDIUM 4.3 CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,_CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to o...

HCL Software ZIE 16.0 CVE