Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2026-42972
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 5.5
CVE-2026-42906
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Windows 10 21h2
10.0.19044.7417 / 10.0.19045.7417+
MEDIUM 6.5
CVE-2026-42907
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
Windows 10 1809
10.0.17763.8880 / 10.0.19044.7417+
HIGH 8.0
CVE-2026-0411
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain admi…
Rbe970 Firmware
4.4.2.2 / 6.3.8.11+
HIGH 7.1
CVE-2026-49742
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media …
Patch available
MEDIUM 5.3
CVE-2026-47351
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to …
Patch available
MEDIUM 6.5
CVE-2026-7542
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compound…
Mitigation only
MEDIUM 6.5
CVE-2026-34905
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unl…
Answer
2.0.1+
MEDIUM 5.5
CVE-2026-41980
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
No fix yet
MEDIUM 6.5
CVE-2026-46443
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a …
Flowise
3.1.2+
MEDIUM 5.3
CVE-2026-11458
A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the…
Mitigation only
HIGH 8.3
CVE-2026-11424
A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authen…
Mitigation only
HIGH 8.3
CVE-2026-11431
A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated u…
Mitigation only
HIGH 7.4
CVE-2026-45300
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the…
Async Http Client
2.15.0 / 3.0.10+
CRITICAL 9.3
CVE-2026-46395
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backe…
Mitigation only
MEDIUM 6.5
CVE-2026-11271
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specifi…
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-47655
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Graph
No fix yet
MEDIUM 6.5
CVE-2026-11209
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-11203
Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted …
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-11182
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-11180
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-11168
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process…
Chrome
149.0.7827.53+
HIGH 8.2
CVE-2025-69755
An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a …
Mitigation only
HIGH 7.5
CVE-2026-50210
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaint…
Connect M6e 5g Firmware
Mitigation only
HIGH 7.5
CVE-2026-49193
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
Connect M6e 5g Firmware
Mitigation only
HIGH 7.5
CVE-2026-49187
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
Connect M6e 5g Firmware
No fix yet
MEDIUM 6.9
CVE-2026-40495
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache bu…
Mitigation only
HIGH 7.3
CVE-2026-36611
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction he…
Mitigation only
HIGH 7.5
CVE-2026-41032
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Mitigation only
CRITICAL 9.6
CVE-2026-32625
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s…
Librechat
0.8.4+