Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7 CVE-2026-6250

Authenticated Format String Injection on TP-Link Tapo C110_CVE-2026-6250

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Extern...

TP-Link Systems Inc. Tapo C110 v2 CVE
CRITICAL 9.8 CVE-2026-49060

WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability_CVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile Ap...

Hippoo Hippoo Mobile App for WooCommerce n/a CVE
HIGH 8.5 CVE-2026-45174

Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization_CVE-2026-45174

Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initializatio...

CyberArk Software, a Palo Alto Networks Company Idira Endpoint Privilege Manager 26.0 CVE
HIGH 7.5 CVE-2026-44890

Netty has Unbounded Direct Memory Consumption in its RedisDecoder_CVE-2026-44890

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and ...

netty netty >= 4.2.0.Final, < 4.2.15.Final CVE
HIGH 7.5 CVE-2026-44250

Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays_CVE-2026-44250

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and ...

netty netty >= 4.2.0.Final, < 4.2.15.Final CVE
HIGH 8.1 CVE-2026-44249

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking_CVE-2026-44249

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2....

netty netty >= 4.2.0.Final, < 4.2.15.Final CVE
HIGH 7.1 CVE-2026-42653

WordPress SliceWP plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability_CVE-2026-42653

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This i...

iova.mihai SliceWP n/a CVE
CRITICAL 9.3 CVE-2026-42647

WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability_CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection....

Beardev JoomSport n/a CVE
CRITICAL 9.3 CVE-2026-39494

WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability_CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blin...

WBW Plugins Product Filter by WBW n/a CVE
HIGH 8.4 CVE-2026-45173

Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure_CVE-2026-45173

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal ...

CyberArk Software, a Palo Alto Networks Company Identity Browser Extensions 26.0.0 CVE