Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-11265

CVE-2026-11265_CVE-2026-11265

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11264

CVE-2026-11264_CVE-2026-11264

Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11263

CVE-2026-11263_CVE-2026-11263

Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromis...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11261

CVE-2026-11261_CVE-2026-11261

Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to p...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11260

CVE-2026-11260_CVE-2026-11260

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11259

CVE-2026-11259_CVE-2026-11259

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy v...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11258

CVE-2026-11258_CVE-2026-11258

Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11257

CVE-2026-11257_CVE-2026-11257

Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a c...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-46493

haxtheweb/haxcms-php uses insecure method for generating salt_CVE-2026-46493

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitabl...

haxtheweb haxcms-php < 26.0.1 CVE
MEDIUM 5.3 CVE-2026-46401

HAX CMS PHP has Insufficient Session Expiration_CVE-2026-46401

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerabi...

haxtheweb issues < 26.0.0 CVE