Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-60639
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.3
CVE-2026-60640
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
Mitigation only
HIGH 8.8
CVE-2026-60633
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
MEDIUM 6.4
CVE-2026-60620
Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported versio…
Jd Edwards Enterpriseone Configurator
No fix yet
MEDIUM 6.6
CVE-2026-60613
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version th…
Peoplesoft Enterprise Campus Software Campus Community
No fix yet
HIGH 8.8
CVE-2026-60603
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version …
Peoplesoft Enterprise Campus Software Campus Community
Mitigation only
MEDIUM 6.7
CVE-2026-60526
Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult…
Jdk
No fix yet
HIGH 8.4
CVE-2026-64877
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Security Center
Mitigation only
HIGH 7.5
CVE-2026-15792
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
Buildkit
0.31.2+
HIGH 8.7
CVE-2026-15724
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …
No fix yet
HIGH 7.5
CVE-2026-16378
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
153.0 / 153.0.0+
HIGH 7.2
CVE-2026-1771
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version…
No fix yet
HIGH 8.2
CVE-2026-47255
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…
No fix yet
MEDIUM 5.4
CVE-2026-58624
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Component org.…
Mina Sshd
2.19.0+
HIGH 8.5
CVE-2026-47198
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl…
No fix yet
MEDIUM 5.3
CVE-2026-44978
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. …
Xrdp
0.10.6.1+
CRITICAL 9.8
CVE-2026-35048
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat…
Mitigation only
MEDIUM 5.8
CVE-2026-63428
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from th…
No fix yet
HIGH 7.5
CVE-2026-42566
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a ma…
Meshtastic Firmware
No fix yet
CRITICAL 10.0
CVE-2026-16117
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's …
Fastify\/http Proxy
11.6.0+
HIGH 8.8
CVE-2026-7755
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration…
Langflow
1.10.1+
MEDIUM 5.3
CVE-2026-49208
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit…
Ux
2.36.0+
HIGH 7.0
CVE-2026-53411
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow…
Workplace Virtual Desktop Infrastructure
6.6.14+
CRITICAL 9.8
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…
Workplace Desktop
6.5.18 / 6.6.15+
CRITICAL 9.8
CVE-2026-44180
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers…
Enterprise Gateway
3.3.0+
HIGH 7.8
CVE-2026-53409
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege vi…
Rooms
No fix yet
HIGH 7.5
CVE-2026-33692
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose c…
No fix yet
MEDIUM 6.1
CVE-2026-54728
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host …
No fix yet
MEDIUM 6.1
CVE-2026-46341
The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify…
No fix yet
MEDIUM 5.5
CVE-2026-50012
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in s…
Squid
7.6+