Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-18759
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by…
No fix yet
HIGH 7.8
CVE-2026-18606
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program …
No fix yet
MEDIUM 6.2
CVE-2026-15430
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …
No fix yet
CRITICAL 9.1
CVE-2026-16534
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du…
No fix yet
HIGH 8.8
CVE-2026-67356
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe…
No fix yet
CRITICAL 9.8
CVE-2026-16256
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…
No fix yet
HIGH 8.8
CVE-2026-16635
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_up…
Mitigation only
HIGH 8.1
CVE-2026-15368
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly c…
No fix yet
HIGH 8.8
CVE-2026-15414
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to …
No fix yet
HIGH 7.5
CVE-2026-14333
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho…
No fix yet
HIGH 8.1
CVE-2026-12251
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist…
No fix yet
MEDIUM 6.6
CVE-2026-65835
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…
No fix yet
HIGH 8.8
CVE-2026-14980
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per…
Websphere Application Server
26.0.0.9+
HIGH 7.5
CVE-2026-12687
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat…
No fix yet
HIGH 8.8
CVE-2026-17969
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbo…
Chrome
151.0.7922.72+
HIGH 8.8
CVE-2026-17956
Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandb…
Chrome
151.0.7922.72+
HIGH 8.8
CVE-2026-17950
Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a…
Chrome
151.0.7922.72+
HIGH 7.5
CVE-2026-17952
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension …
Chrome
151.0.7922.72+
HIGH 8.4
CVE-2026-17877
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege es…
Chrome
151.0.7922.72+
HIGH 7.8
CVE-2026-17863
Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation v…
Chrome
151.0.7922.72+
HIGH 7.8
CVE-2026-17864
Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalat…
Chrome
151.0.7922.72+
HIGH 8.8
CVE-2026-17868
Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafte…
Chrome
151.0.7922.72+
HIGH 7.5
CVE-2026-17816
Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the render…
Chrome
151.0.7922.72+
HIGH 8.8
CVE-2026-17751
Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox…
Chrome
151.0.7922.72+
HIGH 7.1
CVE-2026-17744
Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo…
Chrome
151.0.7922.72+
HIGH 8.8
CVE-2026-12144
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to …
No fix yet
HIGH 7.8
CVE-2026-18107
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an…
No fix yet
HIGH 8.8
CVE-2026-15992
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a…
No fix yet
HIGH 8.8
CVE-2026-14328
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all version…
No fix yet
CRITICAL 9.8
CVE-2026-14545
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end accou…
No fix yet