Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-11436

Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436

A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignFo...

n/a Mage AI 0.9.0 CVE
MEDIUM 6.9 CVE-2026-11437

perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery_CVE-2026-11437

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component...

perfree go-fastdfs-web 1.3.0 CVE
MEDIUM 5.3 CVE-2026-11438

theonedev projects improper authorization_CVE-2026-11438

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. ...

theonedev onedev 15.0.0 CVE
HIGH 8.7 CVE-2026-11413

JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow_CVE-2026-11413

A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the f...

JingDong JD Cloud Box AX6600 4.5.3.r4546 CVE
MEDIUM 4.8 CVE-2026-11434

FluentCMS Blocks Plugin blocks cross site scripting_CVE-2026-11434

A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Pl...

n/a FluentCMS 0.0.5 CVE
HIGH 8.8 CVE-2026-11211

CVE-2026-11211_CVE-2026-11211

Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H...

Google Chrome 149.0.7827.53 CVE
HIGH 8.3 CVE-2026-10971

CVE-2026-10971_CVE-2026-10971

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had comprom...

Google Chrome 149.0.7827.53 CVE
MEDIUM 5.3 CVE-2026-11412

Jinher OA GetFormSn.aspx sql injection_CVE-2026-11412

A weakness has been identified in Jinher OA C6. The affected element is an unknown function of the file /C6/JHSoft.Web.ModuleCount/GetFormSn.aspx. ...

Jinher OA C6 CVE
MEDIUM 4.8 CVE-2026-11411

iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal_CVE-2026-11411

A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDir of the component chatpdf....

iAI Lab PDF AI App 4.21.0 CVE
MEDIUM 5.3 CVE-2026-11406

GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection_CVE-2026-11406

A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component Op...

GL.iNet MT3000 4.4.0 CVE