Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.7 CVE-2026-12463

CVE-2026-12463_CVE-2026-12463

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer ...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12460

CVE-2026-12460_CVE-2026-12460

Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the re...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12457

CVE-2026-12457_CVE-2026-12457

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer proc...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.2 CVE-2026-11975

Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface_CVE-2026-11975

Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execu...

simplcommerce SimplCommerce CVE
MEDIUM 5.1 CVE-2026-10839

Open redirection vulnerability in Password Manager_CVE-2026-10839

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter th...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10837

Open redirection vulnerability in Password Manager_CVE-2026-10837

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that,...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10836

Improper neutralization of HTTP headers in Password Manager_CVE-2026-10836

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A succ...

Password Manager Password Manager CVE
MEDIUM 4.3 CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,_CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to o...

HCL Software ZIE 16.0 CVE
MEDIUM 6.5 CVE-2026-54817

WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability_CVE-2026-54817

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue...

FluxBuilder MStore API n/a CVE
MEDIUM 6.5 CVE-2026-52716

WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerability_CVE-2026-52716

Unauthenticated Arbitrary File Deletion in WorkScout-Core

purethemes WorkScout-Core n/a CVE