Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-42544
Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We…
Mitigation only
MEDIUM 6.2
CVE-2026-34679
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34688
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34666
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34668
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34669
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34670
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…
C2pa
0.7.1 / 0.80.1+
HIGH 7.5
CVE-2026-23825
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera…
Arubaos
8.10.0.22 / 8.12.0.7+
CRITICAL 9.8
CVE-2026-44343
WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allo…
Wgdashboard
4.3.2+
MEDIUM 6.5
CVE-2026-44204
Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass…
Patch available
HIGH 7.3
CVE-2026-35433
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
.net Framework
8.0.27 / 9.0.16+
HIGH 7.3
CVE-2026-32177
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Visual Studio 2022
8.0.27 / 9.0.16+
HIGH 7.8
CVE-2026-20767
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escala…
Quickassist Technology
1.13.0-0021+
HIGH 8.5
CVE-2026-43989
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age…
Patch available
MEDIUM 6.6
CVE-2026-20905
Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial o…
Quickassist Technology
2.6.0-0018+
MEDIUM 6.6
CVE-2026-20717
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial …
Quickassist Technology
1.13.0-0021+
HIGH 8.8
CVE-2025-35990
Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo…
Endpoint Management Assistant
1.14.5.0+
CRITICAL 9.8
CVE-2026-41293
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…
Tomcat
9.0.118 / 10.1.55+
MEDIUM 5.3
CVE-2026-8391
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…
Firefox
150.0.3+
HIGH 7.8
CVE-2026-45391
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command…
Mitigation only
HIGH 8.7
CVE-2026-45392
DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an auth…
Mitigation only
HIGH 7.8
CVE-2026-45393
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr…
Mitigation only
CRITICAL 9.6
CVE-2026-43899
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitig…
Mitigation only
HIGH 7.5
CVE-2026-28936
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, ma…
Ipados
14.8.7 / 18.7.9+
HIGH 8.1
CVE-2026-28907
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, m…
Ipados
18.7.9 / 26.5+
HIGH 7.5
CVE-2026-28860
The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia …
Ipados
14.8.5 / 15.7.5+
HIGH 7.3
CVE-2026-31251
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC …
Mitigation only
CRITICAL 9.4
CVE-2026-42613
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc…
Patch available
HIGH 7.8
CVE-2026-42301
pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the su…
Mitigation only
CRITICAL 9.6
CVE-2026-44336
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…
Praisonai
4.6.34+