Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.8
CVE-2026-34318
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4…
MySQL
after 9.6.0
MEDIUM 6.5
CVE-2026-34313
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…
Financial Services Analytical Applications Infrastructure
Mitigation only
MEDIUM 6.5
CVE-2026-34300
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affecte…
Peoplesoft Enterprise Fin Contracts
Mitigation only
HIGH 7.5
CVE-2026-34305
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …
Weblogic Server
Mitigation only
HIGH 7.5
CVE-2026-34297
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that a…
Hcm Common Architecture
after 12.2.15
MEDIUM 5.3
CVE-2026-34273
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability all…
Goldengate
after 23.10
HIGH 7.5
CVE-2026-22016
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte…
Jre
Mitigation only
MEDIUM 5.4
CVE-2026-22006
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version t…
Peoplesoft Enterprise Hcm Human Resources
Mitigation only
MEDIUM 5.3
CVE-2026-21999
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit…
Xml Database
after 23.26.1
MEDIUM 5.3
CVE-2026-40908
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns t…
Avideo
after 29.0
HIGH 8.8
CVE-2026-40885
goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator …
Goshs
No fix yet
HIGH 7.5
CVE-2026-40584
RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improper…
Ransomlook
1.9.0+
CRITICAL 9.8
CVE-2026-40498
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …
Freescout
1.8.213+
HIGH 7.5
CVE-2026-6782
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Firefox
150.0+
MEDIUM 6.5
CVE-2026-6770
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14…
Firefox
140.10.0 / 150.0+
HIGH 7.5
CVE-2026-6756
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
Firefox
150.0+
MEDIUM 6.3
CVE-2026-31370
Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.
Mitigation only
MEDIUM 6.5
CVE-2026-34839
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that …
Glances
4.5.4+
MEDIUM 6.8
CVE-2026-40490
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect f…
Patch available
HIGH 7.5
CVE-2026-2262
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp…
Mitigation only
MEDIUM 6.5
CVE-2026-40293
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key…
Openfga
1.14.0+
HIGH 7.5
CVE-2025-65104
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQL…
Firebird
3.0.14+
MEDIUM 5.3
CVE-2026-6492
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an u…
Patch available
MEDIUM 6.5
CVE-2026-23777
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…
Powerprotect Data Domain
after 8.5.0.0
CRITICAL 9.8
CVE-2025-15625
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
Pro Cloud Server
Mitigation only
HIGH 7.5
CVE-2026-40245
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disc…
Free5gc
after 4.2.1
CRITICAL 9.4
CVE-2026-40173
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…
Dgraph
25.3.2+
MEDIUM 5.3
CVE-2026-39857
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the cho…
Apostrophecms
4.29.0+
MEDIUM 5.3
CVE-2026-33888
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get…
Apostrophecms
4.29.0+
MEDIUM 6.8
CVE-2026-33220
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe…
Weblate
5.17+