Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2026-8981

Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML_CVE-2026-8981

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to i...

Unknown Custom Block Builder CVE
LOW 2.1 CVE-2026-49738

TYPO3 CMS – Broken Access Control in File Abstraction Layer_CVE-2026-49738

The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator b...

TYPO3 TYPO3 CMS CVE
LOW 3.6 CVE-2026-11764

Data exposed without proper permission_CVE-2026-11764

When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the expo...

pretix pretix 2024.1.0 CVE
LOW 2.4 CVE-2026-41986

CVE-2026-41986_CVE-2026-41986

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

Huawei HarmonyOS 6.1.0 CVE
LOW 3.6 CVE-2026-41974

CVE-2026-41974_CVE-2026-41974

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

Huawei HarmonyOS 4.3.1 CVE
LOW 3.7 CVE-2026-41852

Spring Framework Arbitrary Method Invocation in SpEL Expressions_CVE-2026-41852

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted ...

Spring Spring Framework 7.0.0 CVE
LOW 3.7 CVE-2026-41848

Spring Framework Denial of Service via AntPathMatcher_CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then d...

Spring Spring Framework 7.0.0 CVE
LOW 2 CVE-2026-11623

tmux image.c image_free use after free_CVE-2026-11623

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to ...

n/a tmux 3.6a CVE
LOW 3.1 CVE-2026-11691

CVE-2026-11691_CVE-2026-11691

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...

Google Chrome 149.0.7827.103 CVE
LOW 3.1 CVE-2026-11686

CVE-2026-11686_CVE-2026-11686

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised ...

Google Chrome 149.0.7827.103 CVE