Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-6858

Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS_CVE-2026-6858

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform St...

Unknown Transbank Webpay CVE
HIGH 7.1 CVE-2026-4259

Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions_CVE-2026-4259

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page,...

Unknown ultimate-woocommerce-auction-pro CVE
HIGH 7.3 CVE-2026-9029

Stored XSS via Geomap Panel Template Variable Attribution Injection_CVE-2026-9029

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before g...

Grafana Grafana OSS 12.4.0 CVE
HIGH 7 CVE-2026-6653

libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling_CVE-2026-6653

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-servic...

GNOME libxml2 2.9.11 CVE
HIGH 8.3 CVE-2026-56448

Authenticated Path Traversal in AIL Framework Investigation Downloads Allows Arbitrary File Read_CVE-2026-56448

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authentica...

ail project ail framework CVE
HIGH 8.7 CVE-2026-56446

Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP_CVE-2026-56446

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can i...

misp misp CVE
HIGH 7.1 CVE-2026-56424

Broken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, templates, and decaying models_CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edi...

misp misp CVE
HIGH 8.3 CVE-2026-54100

Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft_CVE-2026-54100

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Window...

Red Hat Red Hat OpenShift Container Platform 4 CVE
HIGH 8.8 CVE-2026-54099

Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters_CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that ...

Red Hat Red Hat OpenShift Container Platform 4 CVE
HIGH 7.7 CVE-2026-42129

Path Traversal in Loki Datasource leads to Internal Information Disclosure_CVE-2026-42129

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin'...

Grafana Grafana OSS CVE