Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-67339
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap…
No fix yet
HIGH 8.3
CVE-2026-67320
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configurat…
No fix yet
HIGH 7.5
CVE-2026-67322
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git…
No fix yet
MEDIUM 5.3
CVE-2026-18059
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …
No fix yet
HIGH 7.5
CVE-2026-14839
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauth…
No fix yet
MEDIUM 6.2
CVE-2026-54785
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_…
No fix yet
MEDIUM 6.5
CVE-2026-45377
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_…
No fix yet
CRITICAL 9.9
CVE-2026-52855
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg…
No fix yet
MEDIUM 6.5
CVE-2026-14928
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce…
No fix yet
MEDIUM 6.5
CVE-2026-14931
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi…
No fix yet
HIGH 7.5
CVE-2026-15048
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re…
No fix yet
HIGH 7.5
CVE-2026-14319
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing…
No fix yet
CRITICAL 9.3
CVE-2026-48499
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…
No fix yet
HIGH 7.5
CVE-2026-41186
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug lis…
Calico
3.21.7 / 3.22.4+
MEDIUM 6.5
CVE-2026-18005
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-18001
Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17975
Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive informat…
Chrome
151.0.7922.72+
MEDIUM 6.2
CVE-2026-17966
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa…
Chrome
151.0.7922.72+
MEDIUM 5.5
CVE-2026-17973
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17892
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17683
Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…
Chrome
151.0.7922.72+
MEDIUM 6.0
CVE-2026-67435
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() …
No fix yet
HIGH 8.3
CVE-2026-67436
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfi…
No fix yet
CRITICAL 9.1
CVE-2026-13697
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…
Undici
7.29.0 / 8.9.0+
HIGH 7.4
CVE-2026-54660
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo…
No fix yet
MEDIUM 5.3
CVE-2026-66489
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
Gridbox
2.20.2+
HIGH 8.7
CVE-2026-58157
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.
This issue affects Apache Traffic S…
Traffic Server
9.2.15 / 10.1.4+
MEDIUM 5.3
CVE-2026-11351
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti…
No fix yet
MEDIUM 6.9
CVE-2026-54659
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver…
No fix yet
HIGH 7.5
CVE-2026-55389
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…
Datamodel Code Generator
0.62.0+