Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access_CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databas...

Apache Software Foundation Apache HTTP Server 2.4.67 and earlier CVE
CRITICAL 9.6 CVE-2026-11697

CVE-2026-11697_CVE-2026-11697

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbo...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.6 CVE-2026-11659

CVE-2026-11659_CVE-2026-11659

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a cr...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.6 CVE-2026-11654

CVE-2026-11654_CVE-2026-11654

Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape v...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.3 CVE-2026-10731

SQL injection in Nemon products_CVE-2026-10731

SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The tw...

Nemon Nemon Trade Energy 2.95.55 CVE
CRITICAL 9.8 CVE-2026-5067

Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key_CVE-2026-5067

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-...

zephyrproject-rtos Zephyr 3.7.0 CVE
CRITICAL 9.6 CVE-2026-11671

CVE-2026-11671_CVE-2026-11671

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a craft...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.6 CVE-2026-11651

CVE-2026-11651_CVE-2026-11651

Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.6 CVE-2026-11638

CVE-2026-11638_CVE-2026-11638

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted...

Google Chrome 149.0.7827.103 CVE
CRITICAL 9.6 CVE-2026-11634

CVE-2026-11634_CVE-2026-11634

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via...

Google Chrome 149.0.7827.103 CVE