Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-12024

CVE-2026-12024_CVE-2026-12024

Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a c...

Google Chrome 149.0.7827.115 CVE
MEDIUM 5.9 CVE-2026-9271

KeepInMind – Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS_CVE-2026-9271

Vulnerability Title

Unknown KeepInMind Dashboard Notes CVE
LOW 3.5 CVE-2026-9269

Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter_CVE-2026-9269

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could...

Unknown Secure Copy Content Protection and Content Locking CVE
HIGH 7.5 CVE-2026-50645

Apache CXF: No restriction on attachment headers per message_CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to unc...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 6.5 CVE-2026-50634

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry_CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the a...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.1 CVE-2026-50633

Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl_CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is ab...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 8.1 CVE-2026-50632

Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory_CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, w...

Apache Software Foundation Apache CXF 4.2.0 CVE
HIGH 7.4 CVE-2026-50631

Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing_CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate m...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 6.5 CVE-2026-50630

Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection_CVE-2026-50630

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' p...

Apache Software Foundation Apache CXF 4.2.0 CVE
MEDIUM 5.3 CVE-2026-50629

Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier_CVE-2026-50629

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control ch...

Apache Software Foundation Apache CXF 4.2.0 CVE