Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-11263

CVE-2026-11263_CVE-2026-11263

Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromis...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11261

CVE-2026-11261_CVE-2026-11261

Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to p...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11260

CVE-2026-11260_CVE-2026-11260

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11259

CVE-2026-11259_CVE-2026-11259

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy v...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11258

CVE-2026-11258_CVE-2026-11258

Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11257

CVE-2026-11257_CVE-2026-11257

Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a c...

Google Chrome 149.0.7827.53 CVE
MEDIUM 5.3 CVE-2026-46401

HAX CMS PHP has Insufficient Session Expiration_CVE-2026-46401

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerabi...

haxtheweb issues < 26.0.0 CVE
MEDIUM 6.5 CVE-2026-46397

haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0_CVE-2026-46397

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerabi...

haxtheweb haxcms-php < 26.0.0 CVE
MEDIUM 6.5 CVE-2026-46357

HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request_CVE-2026-46357

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authen...

haxtheweb haxcms-nodejs < 26.0.0 CVE
MEDIUM 5.3 CVE-2026-45776

Open XDMoD has Broken Access Control via Client-Controlled Session Variable_CVE-2026-45776

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allow...

ubccr xdmod < 11.0.3 CVE