Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-0061

CVE-2026-0061_CVE-2026-0061

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. ...

Google Android 16-qpr2 CVE
MEDIUM 6.2 CVE-2026-0009

CVE-2026-0009_CVE-2026-0009

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no ad...

Google Android 16 CVE
MEDIUM 5.9 CVE-2025-26418

CVE-2025-26418_CVE-2025-26418

In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a mana...

Google Android 15 CVE
MEDIUM 5.9 CVE-2025-22426

CVE-2025-22426_CVE-2025-22426

In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to ...

Google Android 16-qpr2 CVE
MEDIUM 6.1 CVE-2026-10510

GeniexWebView XSS in com.transsion.aiassistantlifestyle_CVE-2026-10510

Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all vers...

TECNO Mobile com.transsion.aiassistantlifestyle v1.3.0.002 CVE
MEDIUM 6.5 CVE-2026-46718

Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution_CVE-2026-46718

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calc...

Apache Software Foundation Apache Calcite 1.5.0 CVE
MEDIUM 5.4 CVE-2026-49782

WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability_CVE-2026-49782

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels....

Elementor Elementor Website Builder n/a CVE
MEDIUM 5.6 CVE-2026-43965

Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion_CVE-2026-43965

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml conten...

Gleam Gleam 0.18.0-rc1 CVE
MEDIUM 5.1 CVE-2026-42795

Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root_CVE-2026-42795

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball...

Gleam Gleam 0.10.0-rc1 CVE
MEDIUM 5.7 CVE-2026-41918

CVE-2026-41918_CVE-2026-41918

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive informa...

Siemens RUGGEDCOM RST2428P CVE