Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-11942

Akaunting 3.1.21 – Stored XSS in delete confirmation modal_CVE-2026-11942

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permissi...

Akaunting Akaunting 3.1.21 CVE
MEDIUM 5.4 CVE-2026-11372

IBM TRIRIGA Cross-Site Scripting Vulnerability_CVE-2026-11372

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embe...

IBM TRIRIGA Application Platform 5.0.2 CVE
NONE THN:6EDDB510298...

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests_THN:6EDDB51029888D4C2E2682D0407BD7BC

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA4IfKMjQxVhpOYdrcCC4ty0vlGBDg_qCZuuvSTvyVWXYPXQlli7qyCZkPdHHuGJp-HVH1s-HGmf_Zqn97o2...

N/A N/A THN
HIGH 8.3 MS:CVE-2026-12468

Chromium: CVE-2026-12468 Inappropriate implementation in Updater_MS:CVE-2026-12468

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-12466

Chromium: CVE-2026-12466 Heap buffer overflow in WebRTC_MS:CVE-2026-12466

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
NONE IMPERVABLOG:7EE...

On-Premises API Security on Kubernetes: What It Actually Looks Like in Practice_IMPERVABLOG:7EE2F10AC3EAE78AF944E8104F323628

## Let’s Talk About Where Your APIs Actually Run **Quick answer:** On-premises API security keeps API discovery, detection, and enforcement inside...

N/A N/A IMPERVABLOG
NONE HACKREAD:7F9E2B...

Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper_HACKREAD:7F9E2B8D9C7C3249BBB6DCA19290C526

A multi-platform malware campaign abuses fake trust signals to infect Windows and Mac users with a crypto clipper packed with 15,500 attacker wallets.

N/A N/A HACKREAD
NONE MALWAREBYTES:C4...

Document delivery scams: What are they and what’s their goal?_MALWAREBYTES:C4E6AC758E13C3CCBD3552439D46014E

One of Malwarebytes' managers recently received a call from scammers pretending to be a document delivery service. The voicemail sounded official:...

N/A N/A MALWAREBYTES
HIGH 8.8 CVE-2026-8157

Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation_CVE-2026-8157

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST AP...

Unknown Vitepos CVE
MEDIUM 5.3 CVE-2026-7859

Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media_CVE-2026-7859

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated...

Unknown Motors CVE