Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-53946

Ghost: Mobiledoc image-size fetch SSRF_CVE-2026-53946

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by is...

TryGhost Ghost >= 6.19.4, < 6.21.1 CVE
MEDIUM 4 CVE-2026-53945

Ghost: Server-side request forgery via DNS rebinding in external request handling_CVE-2026-53945

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DN...

TryGhost Ghost >= 6.0.9, < 6.21.1 CVE
MEDIUM 5.8 CVE-2026-53944

Ghost: Private IP filtering bypass to make server-side requests to internal services_CVE-2026-53944

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that...

TryGhost Ghost >= 6.0.9, < 6.21.1 CVE
MEDIUM 5.7 CVE-2026-49220

Jellyfin: Potential XSS in user management_CVE-2026-49220

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged u...

jellyfin jellyfin < 10.11.9 CVE
MEDIUM 4.7 CVE-2026-13034

CVE-2026-13034_CVE-2026-13034

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer proce...

Google Chrome 149.0.7827.197 CVE
MEDIUM 5.3 CVE-2026-13030

CVE-2026-13030_CVE-2026-13030

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information ...

Google Chrome 149.0.7827.197 CVE
MEDIUM 4.2 CVE-2026-13024

CVE-2026-13024_CVE-2026-13024

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the...

Google Chrome 149.0.7827.197 CVE
MEDIUM 5.3 CVE-2026-13023

CVE-2026-13023_CVE-2026-13023

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain pote...

Google Chrome 149.0.7827.197 CVE
MEDIUM 4.3 CVE-2026-13021

CVE-2026-13021_CVE-2026-13021

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same ori...

Google Chrome 149.0.7827.197 CVE
MEDIUM 5.5 CVE-2025-60471

CVE-2025-60471_CVE-2025-60471

A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows at...

n/a n/a n/a CVE