Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2026-59296
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-…
No fix yet
MEDIUM 6.9
CVE-2026-15576
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate …
No fix yet
HIGH 7.3
CVE-2026-14208
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), …
No fix yet
HIGH 8.7
CVE-2026-77755
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents.
The STIX import code u…
Patch available
HIGH 8.8
CVE-2026-77751
A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export.
MISP object nam…
Patch available
MEDIUM 6.3
CVE-2026-77681
A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/upda…
No fix yet
MEDIUM 5.3
CVE-2026-59323
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded ob…
No fix yet
HIGH 7.5
CVE-2026-47827
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vul…
No fix yet
MEDIUM 6.9
CVE-2026-77710
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import.
The STIX imp…
Patch available
MEDIUM 5.8
CVE-2026-74866
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur…
No fix yet
MEDIUM 5.4
CVE-2026-66797
Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure.
The addAnnotation and listA…
No fix yet
HIGH 8.8
CVE-2026-63046
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex…
No fix yet
HIGH 8.8
CVE-2026-61400
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func…
No fix yet
HIGH 8.8
CVE-2026-50112
SSRF via Metalink Mirror URL Resolution:
An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing…
No fix yet
CRITICAL 9.8
CVE-2026-77264
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas…
No fix yet
MEDIUM 5.3
CVE-2026-19441
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
This issue affects Rush: thr…
No fix yet
HIGH 7.5
CVE-2026-16323
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass…
No fix yet
HIGH 7.2
CVE-2026-75796
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing …
No fix yet
HIGH 8.1
CVE-2026-18781
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after …
No fix yet
MEDIUM 5.3
CVE-2026-16962
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret…
No fix yet
MEDIUM 6.8
CVE-2026-16959
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its …
No fix yet
HIGH 7.2
CVE-2026-16576
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some…
No fix yet
MEDIUM 5.3
CVE-2026-16575
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission …
No fix yet
MEDIUM 6.8
CVE-2026-14601
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen…
No fix yet
MEDIUM 5.3
CVE-2026-13736
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,…
No fix yet
MEDIUM 5.4
CVE-2025-15671
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr…
No fix yet
HIGH 7.2
CVE-2026-18409
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version…
No fix yet
CRITICAL 9.3
CVE-2026-76158
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacke…
No fix yet
MEDIUM 5.3
CVE-2026-76131
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to…
No fix yet
HIGH 7.7
CVE-2026-73267
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete Clus…
No fix yet