Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-12438

CVE-2026-12438_CVE-2026-12438

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the rende...

Google Chrome 149.0.7827.155 CVE
HIGH 8.3 CVE-2026-12437

CVE-2026-12437_CVE-2026-12437

Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process t...

Google Chrome 149.0.7827.155 CVE
MEDIUM 6.2 CVE-2026-11975

Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface_CVE-2026-11975

Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execu...

simplcommerce SimplCommerce CVE
HIGH 8.4 CVE-2026-11858

Missing authorization in Quanos SCHEMA ST4 Client Update Service allows arbitrary file overwrite as SYSTEM_CVE-2026-11858

Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHO...

Quanos Solutions GmbH SCHEMA ST4 SCHEMA ST4 on-premises, all versions CVE
HIGH 8.4 CVE-2026-11857

Insecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Service allows local privilege escalation_CVE-2026-11857

Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in t...

Quanos Solutions GmbH SCHEMA ST4 SCHEMA ST4 on-premises, all versions CVE
MEDIUM 5.1 CVE-2026-10839

Open redirection vulnerability in Password Manager_CVE-2026-10839

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter th...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10837

Open redirection vulnerability in Password Manager_CVE-2026-10837

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that,...

Password Manager Password Manager CVE
MEDIUM 5.1 CVE-2026-10836

Improper neutralization of HTTP headers in Password Manager_CVE-2026-10836

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A succ...

Password Manager Password Manager CVE
LOW 3.1 CVE-2025-62340

HCL iControl was affected by Inadequate Session Timeout vulnerability_CVE-2025-62340

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to ...

HCL Software iControl v4.2.0 CVE
MEDIUM 4.3 CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,_CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to o...

HCL Software ZIE 16.0 CVE