Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-12011

CVE-2026-12011_CVE-2026-12011

Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to...

Google Chrome 149.0.7827.115 CVE
HIGH 8.3 CVE-2026-12010

CVE-2026-12010_CVE-2026-12010

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process ...

Google Chrome 149.0.7827.115 CVE
HIGH 8.3 CVE-2026-12009

CVE-2026-12009_CVE-2026-12009

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compr...

Google Chrome 149.0.7827.115 CVE
HIGH 8.3 CVE-2026-12008

CVE-2026-12008_CVE-2026-12008

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to...

Google Chrome 149.0.7827.115 CVE
HIGH 8.8 CVE-2026-12007

CVE-2026-12007_CVE-2026-12007

Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML p...

Google Chrome 149.0.7827.115 CVE
HIGH 7.5 CVE-2026-45170

Idira Privilege Cloud Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation_CVE-2026-45170

Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not...

CyberArk Software, a Palo Alto Networks Company PAM SH Connector 1.1.0 CVE
MEDIUM 6.4 CVE-2026-9125

The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute_CVE-2026-9125

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] sho...

2winfactor Presto Player CVE
HIGH 8.8 CVE-2026-11933

Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion_CVE-2026-11933

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An aut...

MongoDB MongoDB 8.3.0, 8.2.0, 8.0.0, 7.0.0, 6.0, 5.0, 4.4.0 CVE
MEDIUM 4.3 CVE-2026-49482

ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite_CVE-2026-49482

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wil...

MacWarrior clipbucket-v5 < 5.5.3 - #141 CVE
NONE 7232ACFB-AE9E-

RISC-V-In-Proactive-computer-Security-PCS_7232ACFB-AE9E-5288-A52D-C6F60CDEA648

Exploring RISC-V in Proactive Computer Security PCS PUK project - Department of Computer Science, University of Copenhagen Project by Claes Refsgaa...

N/A N/A GITHUBEXPLOIT