Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.6
CVE-2026-30304
In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f…
Ai Code
after 3.12.4
HIGH 7.2
CVE-2025-69986
A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length …
Mitigation only
HIGH 7.3
CVE-2026-4982
A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on …
Mitigation only
HIGH 7.5
CVE-2025-59028
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invali…
Dovecot
2.4.3 / 3.1.2+
HIGH 7.5
CVE-2025-59032
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin…
Dovecot
2.4.3 / 3.1.3+
CRITICAL 9.8
CVE-2026-33729
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to…
Openfga
1.13.1+
MEDIUM 6.5
CVE-2026-29905
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image up…
Kirby
after 5.1.4
CRITICAL 9.8
CVE-2025-55270
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…
Aftermarket Cloud
Mitigation only
HIGH 7.3
CVE-2026-4860
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file sr…
Mitigation only
HIGH 7.5
CVE-2026-33285
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mecha…
Liquidjs
10.25.1+
HIGH 7.5
CVE-2026-33287
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS …
Liquidjs
10.25.1+
HIGH 7.5
CVE-2026-33218
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which …
Nats Server
2.11.15 / 2.12.6+
HIGH 7.5
CVE-2026-28894
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS …
Ipados
14.8.5 / 15.7.5+
MEDIUM 5.5
CVE-2026-28852
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S…
Ipados
15.7.5 / 18.7.7+
HIGH 8.4
CVE-2026-28821
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue …
macOS
14.8.5 / 15.7.5+
MEDIUM 5.3
CVE-2026-20686
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user…
Ipados
26.3+
HIGH 8.7
CVE-2026-3912
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows inf…
Mitigation only
HIGH 7.5
CVE-2026-33332
NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-c…
Nicegui
3.9.0+
HIGH 8.8
CVE-2026-22559
An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engin…
Mitigation only
MEDIUM 5.3
CVE-2026-33769
Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs …
Astro
5.18.1+
CRITICAL 9.8
CVE-2026-4755
CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
Android Imagemagick7
7.1.2-11+
HIGH 7.5
CVE-2026-33250
Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specia…
Patch available
HIGH 7.5
CVE-2025-15606
A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted request…
Td W8961nd Firmware
250925+
HIGH 7.8
CVE-2026-4538
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation …
Pytorch
Patch available
MEDIUM 5.3
CVE-2026-3641
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin reg…
Mitigation only
MEDIUM 5.3
CVE-2026-3460
The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This …
Mitigation only
HIGH 7.5
CVE-2026-33151
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially c…
Socket.io Parser
3.3.5 / 3.4.4+
MEDIUM 5.4
CVE-2026-4438
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 t…
Glibc
after 2.43
HIGH 8.2
CVE-2026-31805
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu…
Discourse
2026.1.2 / 2026.2.1+
HIGH 8.8
CVE-2026-4451
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the r…
Chrome
146.0.7680.153+