Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.4 CVE-2026-8853

MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter_CVE-2026-8853

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1...

websoudan MW WP Form CVE
MEDIUM 6.4 CVE-2026-8613

aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting_CVE-2026-8613

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions u...

smub aThemes Addons for Elementor CVE
MEDIUM 6.9 CVE-2026-29115

CVE-2026-29115_CVE-2026-29115

A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering a...

Dahua IPC/SD Affected products are limited to certain models of IPC and SD devices with a build time before March 26, 2026. CVE
MEDIUM 5.3 CVE-2026-11815

Insecure Deserialization via MITM in Layer 7 Policy Manager_CVE-2026-11815

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitra...

Broadcom Layer 7 API Gateway 11.2.1 CVE
MEDIUM 5.3 CVE-2026-24720

File Station 5_CVE-2026-24720

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user...

QNAP Systems Inc. File Station 5 5.5.0 CVE
MEDIUM 5.1 CVE-2026-24717

QTS, QuTS hero_CVE-2026-24717

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acco...

QNAP Systems Inc. QTS 5.2.0 CVE
MEDIUM 5.1 CVE-2026-24716

QTS, QuTS hero_CVE-2026-24716

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.0 CVE
MEDIUM 5.3 CVE-2026-22899

File Station 5_CVE-2026-22899

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then explo...

QNAP Systems Inc. File Station 5 5.5.0 CVE
MEDIUM 6.9 CVE-2025-66281

QTS, QuTS hero_CVE-2025-66281

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit ...

QNAP Systems Inc. QTS 5.2.0 CVE
MEDIUM 5.1 CVE-2025-66280

QTS, QuTS hero_CVE-2025-66280

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an a...

QNAP Systems Inc. QTS 5.2.0 CVE