Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2026-10868
A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::…
Patch available
HIGH 7.8
CVE-2026-49189
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-8206
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al…
Mitigation only
MEDIUM 6.8
CVE-2026-0086
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to loca…
Android
Mitigation only
HIGH 7.8
CVE-2026-0089
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This cou…
Android
Mitigation only
HIGH 7.8
CVE-2026-0091
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local…
Android
Mitigation only
MEDIUM 6.2
CVE-2026-0046
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This c…
Android
Mitigation only
MEDIUM 6.8
CVE-2026-0048
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead…
Android
Mitigation only
MEDIUM 6.2
CVE-2026-0055
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du…
Android
Mitigation only
HIGH 7.8
CVE-2026-0009
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no addi…
Android
Mitigation only
MEDIUM 6.3
CVE-2026-10217
A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.g…
Mitigation only
MEDIUM 5.7
CVE-2026-48210
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default …
Otrs
Mitigation only
HIGH 8.8
CVE-2026-7465
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to…
Mitigation only
CRITICAL 9.9
CVE-2026-47744
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel…
Mitigation only
CRITICAL 9.9
CVE-2026-45632
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. …
Mitigation only
CRITICAL 9.3
CVE-2026-45043
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi…
Mitigation only
HIGH 8.8
CVE-2026-9999
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sa…
Chrome
148.0.7778.216+
CRITICAL 9.6
CVE-2026-9918
Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a…
Chrome
148.0.7778.216+
HIGH 8.3
CVE-2026-9892
Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer p…
Chrome
148.0.7778.216+
CRITICAL 9.8
CVE-2026-8809
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu…
Mitigation only
HIGH 8.8
CVE-2026-46837
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12…
E Business Suite
after 12.2.15
CRITICAL 9.9
CVE-2026-46824
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported …
Universal Work Queue
after 12.2.15
HIGH 8.8
CVE-2026-46827
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…
E Business Suite
after 12.2.15
CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…
E Business Suite
after 12.2.15
HIGH 8.7
CVE-2026-44543
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with perm…
Local Path Provisioner
0.0.36+
CRITICAL 9.3
CVE-2026-8980
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the pa…
Mitigation only
HIGH 8.8
CVE-2026-6226
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. T…
Mitigation only
HIGH 8.5
CVE-2026-9789
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P…
Mitigation only
HIGH 8.8
CVE-2026-45716
Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin mi…
Mitigation only
HIGH 8.8
CVE-2026-8787
The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This i…
Mitigation only