Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.2 CVE-2026-12456

CVE-2026-12456_CVE-2026-12456

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.2 CVE-2026-12453

CVE-2026-12453_CVE-2026-12453

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rend...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.5 CVE-2026-12450

CVE-2026-12450_CVE-2026-12450

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive informatio...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.3 CVE-2026-12446

CVE-2026-12446_CVE-2026-12446

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafte...

Google Chrome 149.0.7827.155 CVE
MEDIUM 5.5 CVE-2026-12444

CVE-2026-12444_CVE-2026-12444

Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive infor...

Google Chrome 149.0.7827.155 CVE
MEDIUM 4.3 CVE-2025-48571

CVE-2025-48571_CVE-2025-48571

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could...

Google Android 17 CVE
HIGH 7.1 CVE-2026-9570

Taskbuilder < 5.0.8 - Reflected XSS via Shortcode_CVE-2026-9570

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend pa...

Unknown Taskbuilder CVE
MEDIUM 5.3 CVE-2026-8383

LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API_CVE-2026-8383

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allo...

Unknown LearnPress CVE
HIGH 7.1 CVE-2026-8089

weMail < 2.1.3 - Reflected Cross-Site Scripting_CVE-2026-8089

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not prope...

Unknown weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce CVE
MEDIUM 5.9 CVE-2026-7850

WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute_CVE-2026-7850

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displ...

Unknown WP Magnific Popup CVE