Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-11097

CVE-2026-11097_CVE-2026-11097

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via ...

Google Chrome 149.0.7827.53 CVE
HIGH 7.4 CVE-2026-10973

CVE-2026-10973_CVE-2026-10973

Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chr...

Google Chrome 149.0.7827.53 CVE
CRITICAL 9.6 CVE-2026-10972

CVE-2026-10972_CVE-2026-10972

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a cr...

Google Chrome 149.0.7827.53 CVE
HIGH 7.4 CVE-2026-10968

CVE-2026-10968_CVE-2026-10968

Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10966

CVE-2026-10966_CVE-2026-10966

Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vi...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-10955

CVE-2026-10955_CVE-2026-10955

Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory ac...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.4 CVE-2026-9281

Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension)_CVE-2026-9281

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cr...

litonice13 Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits CVE
MEDIUM 4.3 CVE-2026-9008

Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes_CVE-2026-9008

The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_un...

webvitaly Page-list CVE
HIGH 7.2 CVE-2026-8901

Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data_CVE-2026-8901

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site...

plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More CVE
HIGH 7.2 CVE-2026-8438

All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path_CVE-2026-8438

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and incl...

davidanderson All-In-One Security (AIOS) – Security and Firewall CVE