Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-50328
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.3
CVE-2026-15757
A security flaw was discovered in the NETGEAR DGND3700v1 that could
allow someone on the same local WiFi network to send unauthorized commands to
the…
No fix yet
HIGH 7.8
CVE-2026-55899
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20175+
MEDIUM 5.3
CVE-2026-6790
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i…
Jetty
9.4.61 / 10.0.29+
MEDIUM 6.5
CVE-2026-13699
In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point …
Kuksa
No fix yet
CRITICAL 9.3
CVE-2026-22102
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in…
Mitigation only
MEDIUM 5.3
CVE-2026-15531
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function…
Patch available
MEDIUM 6.3
CVE-2026-15535
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d…
Patch available
MEDIUM 6.3
CVE-2026-15529
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py…
Patch available
HIGH 7.2
CVE-2026-3576
The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all version…
Mitigation only
MEDIUM 5.9
CVE-2026-11914
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
No fix yet
HIGH 7.5
CVE-2026-40454
Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client.
Out-of-bounds reads in IoTDB C++ client TsBlock deserializer …
Mitigation only
HIGH 7.5
CVE-2026-15288
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and i…
Mitigation only
MEDIUM 6.5
CVE-2026-0282
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web in…
Pan Os
11.1.16 / 11.2.13+
HIGH 7.5
CVE-2026-51606
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP …
Mitigation only
MEDIUM 6.5
CVE-2026-51598
An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, networ…
Mitigation only
CRITICAL 9.8
CVE-2026-51599
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remot…
No fix yet
CRITICAL 9.4
CVE-2025-58146
There are multiple issues.
1. Updates to the XAPI database sanitise input strings, but try
generating the notification using the unsanitised in…
No fix yet
HIGH 8.3
CVE-2026-15122
Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromise…
Chrome
150.0.7871.115+
MEDIUM 6.3
CVE-2026-15105
A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp …
No fix yet
HIGH 8.8
CVE-2026-10037
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma…
Mitigation only
HIGH 7.5
CVE-2026-59724
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enable…
Engine.io
6.6.7+
CRITICAL 9.1
CVE-2026-41042
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's …
Mitigation only
HIGH 7.5
CVE-2026-54234
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative dec…
Vllm
0.24.0+
CRITICAL 10.0
CVE-2026-48316
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
HIGH 7.3
CVE-2026-49042
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0.
Us…
Camel
4.18.3 / 4.21.0+
HIGH 7.3
CVE-2026-46587
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…
Camel
4.14.8 / 4.18.3+
HIGH 7.3
CVE-2026-46588
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-55994
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-56140
Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-s…
Camel
4.14.8 / 4.18.3+