Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-12295

Sandbox escape in the DOM: Navigation component_CVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 1...

Mozilla Firefox 115.37 CVE
CRITICAL 9.6 CVE-2026-12294

Sandbox escape in the DOM: Workers component_CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152,...

Mozilla Firefox 115.37 CVE
CRITICAL 9.8 CVE-2026-12293

Use-after-free in the Graphics: WebGPU component_CVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
CRITICAL 9.8 CVE-2026-55740

SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter_CVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vuln...

Nur-Alam39 bus-ticket CVE
CRITICAL 9.6 CVE-2026-55742

Cotonti CSRF in admin.rights.php allows privilege escalation_CVE-2026-55742

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/ad...

Cotonti Cotonti 1.0.0 CVE
CRITICAL 10 CVE-2026-28573

CVE-2026-28573_CVE-2026-28573

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of serv...

Google Android 14 CVE
CRITICAL 9.3 CVE-2025-10560

Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources_CVE-2025-10560

Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries...

Silver Leaf Technologies, Inc. Worksnaps.net Worksnaps Worksnaps before 1.6.20260201 CVE
CRITICAL 9.3 CVE-2026-8024

Deserialization vulnerability in ibaPDA and ibaDatCoordinator_CVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access...

iba ibaPDA 1.0.0 CVE
CRITICAL 9.8 CVE-2026-54419

PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query_CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) con...

claudiopizzillo PIAF-HMS CVE
CRITICAL 9.3 CVE-2026-11718

CVE-2026-11718_CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When th...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.0.0 CVE