Skip to main content
AdvisoryLoom

CYBERSECURITY INTELLIGENCE

News that matters, without the noise.

Search current cybersecurity reporting locally in this app. Search terms are not sent to AdvisoryLoom. The Professional plan adds Watchlists, structured My Intelligence, and AI briefings.

Private search: the term stays in this browser and is matched against a generic content feed.

LATEST COVERAGE

Vendor Advisories

2,224 stories

CVE-2026-57980

Medium Severity Description Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized

Open Original Publisher ↗

CVE-2026-62387

High Severity Description The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration

Open Original Publisher ↗

CVE-2026-62386

High Severity Description The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL

Open Original Publisher ↗

CVE-2026-62241

Critical Severity Description clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret (‘clawvet-dev-secret-change-me’) in auth.ts

Open Original Publisher ↗