Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-50602
A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 b…
Fix unknown
HIGH 8.6
CVE-2026-73664
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
MEDIUM 6.3
CVE-2026-50544
NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default ins…
No fix yet
MEDIUM 6.8
CVE-2026-65940
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
No fix yet
HIGH 7.8
CVE-2026-14478
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC mess…
No fix yet
MEDIUM 5.5
CVE-2026-48790
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s…
No fix yet
HIGH 7.0
CVE-2025-0046
Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.
No fix yet
HIGH 7.8
CVE-2026-63522
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
Azure Sql Database
No fix yet
MEDIUM 6.0
CVE-2026-69108
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privileg…
No fix yet
HIGH 7.2
CVE-2026-4757
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…
No fix yet
MEDIUM 5.5
CVE-2026-63623
A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was…
No fix yet
MEDIUM 6.2
CVE-2026-15430
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …
No fix yet
MEDIUM 5.5
CVE-2026-68563
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data`…
No fix yet
CRITICAL 9.3
CVE-2026-48499
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…
No fix yet
MEDIUM 5.5
CVE-2026-64707
A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Se…
Ipados
14.8.8 / 15.7.8+
HIGH 8.8
CVE-2026-61892
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
No fix yet
HIGH 7.8
CVE-2026-16157
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside…
No fix yet
MEDIUM 6.3
CVE-2026-62519
Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte…
E Business Suite
after 12.2.15
CRITICAL 9.4
CVE-2026-61186
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is af…
Agile Engineering Data Management
No fix yet
CRITICAL 9.1
CVE-2026-61155
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is a…
Commerce Guided Search Platform Services
No fix yet
HIGH 7.1
CVE-2026-60659
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily expl…
Solaris
No fix yet
HIGH 7.3
CVE-2026-63358
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' functio…
Filegator
7.14.2+
HIGH 7.2
CVE-2026-44878
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the …
No fix yet
MEDIUM 5.5
CVE-2026-65065
Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW.
The se…
No fix yet
MEDIUM 6.2
CVE-2026-64613
Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW.
The segment is created …
No fix yet
MEDIUM 6.9
CVE-2026-47134
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk p…
No fix yet
HIGH 8.8
CVE-2026-49445
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embe…
Cilium
1.17.14 / 1.18.8+
MEDIUM 6.1
CVE-2026-15779
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the pat…
Mitigation only
CRITICAL 9.1
CVE-2026-53486
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…
Mitigation only