Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-9987
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsor…
Mitigation only
MEDIUM 5.0
CVE-2026-41610
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …
Visual Studio Code
1.119.1+
MEDIUM 6.5
CVE-2026-40374
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
Power Automate For Desktop
2.67+
HIGH 7.5
CVE-2026-40379
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Entra Id
No fix yet
CRITICAL 9.8
CVE-2026-43992
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…
Patch available
HIGH 7.3
CVE-2026-42498
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache…
Tomcat
9.0.118 / 10.1.55+
CRITICAL 9.1
CVE-2026-45091
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp…
Mitigation only
MEDIUM 5.3
CVE-2026-7626
The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_paymen…
Mitigation only
HIGH 7.7
CVE-2026-43885
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.j…
Patch available
HIGH 8.2
CVE-2026-42564
jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-ic…
Mitigation only
HIGH 7.5
CVE-2026-28976
An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.
macOS
26.5+
HIGH 7.5
CVE-2026-28962
This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.…
Ipados
18.7.9 / 26.5+
MEDIUM 5.5
CVE-2026-28958
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,…
Ipados
26.5+
MEDIUM 6.5
CVE-2026-28920
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS…
Ipados
14.8.7 / 15.7.7+
MEDIUM 6.5
CVE-2026-28922
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An ap…
macOS
14.8.7 / 15.7.7+
MEDIUM 6.9
CVE-2026-42871
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive erro…
Mitigation only
MEDIUM 5.3
CVE-2026-34093
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with p…
Mediawiki
1.43.7 / 1.44.4+
HIGH 7.7
CVE-2026-44738
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray…
Grav
2.0.0+
HIGH 7.5
CVE-2026-34087
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth.
This issue affects OATHAuth: from * befor…
Mediawiki
1.43.7 / 1.44.4+
HIGH 7.5
CVE-2026-34088
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This issue affects MediaWiki: from * bef…
Mediawiki
1.43.7 / 1.44.4+
HIGH 7.5
CVE-2026-34090
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser.
This issue affects CheckUser: from 1.45.…
Checkuser
1.45.2+
HIGH 7.5
CVE-2026-34091
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This issue affects MediaWiki: from * bef…
Mediawiki
1.43.7 / 1.44.4+
HIGH 7.5
CVE-2026-34092
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with p…
Mediawiki
1.43.7 / 1.44.4+
MEDIUM 6.3
CVE-2026-42333
Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts…
Patch available
MEDIUM 5.3
CVE-2026-8198
The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Infor…
Mitigation only
MEDIUM 5.1
CVE-2026-42213
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…
Patch available
CRITICAL 9.1
CVE-2026-25199
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudSt…
Cloudstack
4.22.0.1+
MEDIUM 5.5
CVE-2026-43942
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handle…
Electerm
after 3.8.15
CRITICAL 9.6
CVE-2026-42880
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a …
Argo Cd
3.2.11 / 3.3.9+
HIGH 7.5
CVE-2026-42826
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
Azure Devops
No fix yet