Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-44274

CVE-2026-44274_CVE-2026-44274

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privilege...

Dell Wyse Management Suite (WMS) CVE
HIGH 8.8 CVE-2026-44272

CVE-2026-44272_CVE-2026-44272

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL I...

Dell Wyse Management Suite (WMS) CVE
HIGH 8.1 CVE-2026-44271

CVE-2026-44271_CVE-2026-44271

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL I...

Dell Wyse Management Suite (WMS) CVE
HIGH 7.5 MS:CVE-2026-12462

Chromium: CVE-2026-12462 Use after free in Media_MS:CVE-2026-12462

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-12454

Chromium: CVE-2026-12454 Race in Safe Browsing_MS:CVE-2026-12454

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.1 CVE-2025-66336

Apache Doris MCP Server: SQL injection leading the authentication bypass_CVE-2025-66336

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated i...

Apache Software Foundation Apache Doris MCP Server 0.1.0 CVE
HIGH 7.5 CVE-2025-66389

CVE-2025-66389_CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_web...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-10845

IBM WebSphere Application Server is affected by an authentication bypass vulnerability_CVE-2026-10845

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicat...

IBM WebSphere Application Server 8.5.0 CVE
HIGH 7 CVE-2026-56109

ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c_CVE-2026-56109

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows ...

alsa-project alsa-lib CVE
HIGH 8.1 CVE-2026-55388

piscina: Prototype Pollution Gadget → RCE via inherited options.filename_CVE-2026-55388

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename opt...

piscinajs piscina < 4.9.3 CVE