Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.0
CVE-2026-11386
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so…
No fix yet
MEDIUM 6.4
CVE-2026-56678
9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using…
Mitigation only
HIGH 7.1
CVE-2026-50144
ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 a…
Mitigation only
CRITICAL 9.6
CVE-2026-53513
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST…
Better Auth\/sso
1.6.11+
MEDIUM 6.2
CVE-2026-14961
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. T…
Mitigation only
HIGH 7.5
CVE-2026-59955
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi…
Mitigation only
HIGH 7.5
CVE-2026-59954
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi…
Mitigation only
HIGH 7.5
CVE-2026-20153
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…
Roomos
11.32.6.0 / 11.39.1.1+
HIGH 7.3
CVE-2026-61427
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the s…
Mitigation only
MEDIUM 6.3
CVE-2026-56349
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instruct…
Mitigation only
CRITICAL 9.0
CVE-2026-56398
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type i…
Open Webui
0.9.5+
HIGH 7.5
CVE-2026-48351
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker …
C2pa
after 0.84.0
HIGH 7.5
CVE-2026-48352
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker …
C2pa
after 0.84.0
MEDIUM 5.5
CVE-2026-48353
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could ex…
C2pa
after 0.84.0
MEDIUM 6.2
CVE-2026-48302
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker …
C2pa
after 0.84.0
MEDIUM 6.8
CVE-2026-48312
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l…
C2pa
after 0.84.0
CRITICAL 9.3
CVE-2026-48334
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current use…
Illustrator
29.8.9 / 30.6+
HIGH 7.7
CVE-2026-48328
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could …
Coldfusion
Mitigation only
CRITICAL 9.6
CVE-2026-48284
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user…
Coldfusion
Mitigation only
MEDIUM 5.9
CVE-2026-48308
Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
Premiere Pro
after 26.2.2
MEDIUM 6.2
CVE-2026-47470
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local att…
No fix yet
MEDIUM 6.5
CVE-2026-15778
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the r…
Chrome
150.0.7871.125+
HIGH 8.3
CVE-2026-15769
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who h…
Chrome
150.0.7871.125+
MEDIUM 5.3
CVE-2026-15771
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised…
Chrome
150.0.7871.125+
CRITICAL 9.8
CVE-2026-13001
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle…
Mitigation only
MEDIUM 5.4
CVE-2026-62656
A
security flaw was found in certain NETGEAR RAX models that could allow
a logged-in user to send specially crafted requests to the router and run
un…
Mitigation only
MEDIUM 5.5
CVE-2026-55124
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.10417.20175 / 16.0.19725.20434+
HIGH 7.8
CVE-2026-50670
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 7.8
CVE-2026-50417
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-50370
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+