Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2026-19628
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to …
No fix yet
HIGH 7.2
CVE-2026-19771
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component …
No fix yet
HIGH 8.8
CVE-2026-73667
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates u…
No fix yet
HIGH 7.5
CVE-2026-73660
FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS…
No fix yet
HIGH 7.6
CVE-2026-73662
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg1…
No fix yet
HIGH 8.9
CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP…
No fix yet
HIGH 8.1
CVE-2026-53790
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying m…
No fix yet
HIGH 7.5
CVE-2026-73623
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary co…
No fix yet
HIGH 8.8
CVE-2026-73625
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling gi…
No fix yet
CRITICAL 9.4
CVE-2026-73483
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…
No fix yet
CRITICAL 9.8
CVE-2026-49819
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…
No fix yet
MEDIUM 6.1
CVE-2026-17431
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _styl…
No fix yet
CRITICAL 9.6
CVE-2026-49481
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d…
No fix yet
HIGH 7.8
CVE-2026-16695
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci…
I Access Client Solutions
No fix yet
HIGH 7.3
CVE-2026-13476
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges …
Informix Dynamic Server
No fix yet
MEDIUM 6.3
CVE-2026-73412
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly c…
No fix yet
CRITICAL 9.2
CVE-2026-73414
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`…
No fix yet
CRITICAL 9.9
CVE-2026-63298
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje…
No fix yet
HIGH 8.8
CVE-2026-17417
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach…
I
No fix yet
HIGH 8.8
CVE-2026-17642
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem…
I
No fix yet
HIGH 7.2
CVE-2026-12005
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…
Security Verify Access
No fix yet
HIGH 8.3
CVE-2026-18235
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val…
I
after 7.6
MEDIUM 6.3
CVE-2026-17420
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el…
I
after 7.6
MEDIUM 6.5
CVE-2026-17248
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme…
I
after 7.6
CRITICAL 9.8
CVE-2026-16956
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…
Db2 Mirror For I
after 7.6
HIGH 8.8
CVE-2026-16856
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
I
No fix yet
HIGH 8.8
CVE-2026-16906
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …
I
No fix yet
HIGH 7.5
CVE-2026-48553
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr…
No fix yet
HIGH 7.5
CVE-2026-48554
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr…
No fix yet
HIGH 8.8
CVE-2026-18683
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…
I
No fix yet