Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-43714
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequ…
Ipados
14.8.8 / 15.7.8+
MEDIUM 6.9
CVE-2026-54272
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr…
No fix yet
MEDIUM 5.3
CVE-2026-46452
Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resultin…
Nimble
1.10.0+
HIGH 8.8
CVE-2026-54120
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Surface Management Services
No fix yet
HIGH 8.2
CVE-2026-65604
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies…
No fix yet
CRITICAL 10.0
CVE-2026-47668
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…
No fix yet
CRITICAL 9.0
CVE-2026-16723
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…
No fix yet
HIGH 7.3
CVE-2026-16632
A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/w…
No fix yet
MEDIUM 6.5
CVE-2026-13057
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls.
In sharded topologies, the $sea…
MongoDB
8.0.28 / 8.2.12+
HIGH 7.2
CVE-2026-46737
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …
Powerprotect Data Manager
20.2+
HIGH 7.2
CVE-2026-46738
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …
Powerprotect Data Manager
20.2+
HIGH 7.2
CVE-2026-40712
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …
Powerprotect Data Manager
20.2+
HIGH 7.2
CVE-2026-40714
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with re…
Powerprotect Data Manager
20.2+
HIGH 7.5
CVE-2026-55973
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the la…
Unbound
1.25.2+
HIGH 7.5
CVE-2026-57600
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive …
No fix yet
MEDIUM 6.9
CVE-2026-16551
Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation.
This issue affects OpenCanary 0.9.8 only.
No fix yet
MEDIUM 5.4
CVE-2026-16415
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of …
Chrome
150.0.7871.182+
HIGH 8.8
CVE-2026-16421
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbo…
Chrome
150.0.7871.182+
HIGH 7.5
CVE-2026-16422
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged netwo…
Chrome
150.0.7871.182+
HIGH 7.8
CVE-2026-16414
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a s…
Chrome
150.0.7871.182+
MEDIUM 6.3
CVE-2026-62519
Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte…
E Business Suite
after 12.2.15
HIGH 8.1
CVE-2026-61160
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). …
Commerce Experience Manager
Mitigation only
MEDIUM 5.8
CVE-2026-61079
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26…
Goldengate
after 23.26.2.0.0
CRITICAL 9.9
CVE-2026-60719
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.…
Bi Publisher
No fix yet
HIGH 8.0
CVE-2026-60648
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 8.0
CVE-2026-60650
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60634
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60636
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
Mitigation only
HIGH 8.8
CVE-2026-60637
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60638
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet