Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2026-77392
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of th…
No fix yet
HIGH 8.8
CVE-2026-76157
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unau…
No fix yet
CRITICAL 9.4
CVE-2026-76156
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execut…
No fix yet
CRITICAL 9.3
CVE-2026-76155
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the…
No fix yet
CRITICAL 9.8
CVE-2026-77651
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depen…
No fix yet
CRITICAL 9.8
CVE-2026-77650
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue…
No fix yet
CRITICAL 9.8
CVE-2026-77649
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depe…
No fix yet
HIGH 8.7
CVE-2026-16520
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.…
No fix yet
CRITICAL 9.8
CVE-2026-77647
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to inc…
No fix yet
MEDIUM 6.7
CVE-2026-77113
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary fi…
Patch available
HIGH 7.7
CVE-2026-77646
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited thr…
No fix yet
CRITICAL 9.2
CVE-2026-77645
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…
No fix yet
CRITICAL 9.3
CVE-2026-77644
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
No fix yet
HIGH 7.5
CVE-2026-77642
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact …
No fix yet
HIGH 8.5
CVE-2026-72860
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the desti…
Patch available
HIGH 8.6
CVE-2026-72848
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf ur…
No fix yet
MEDIUM 6.4
CVE-2026-72846
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat…
No fix yet
CRITICAL 9.8
CVE-2026-72843
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, wh…
No fix yet
HIGH 7.5
CVE-2026-72818
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked…
No fix yet
MEDIUM 6.5
CVE-2026-70105
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
No fix yet
HIGH 7.7
CVE-2026-69855
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
No fix yet
CRITICAL 9.9
CVE-2026-69851
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 10.0
CVE-2026-69836
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
No fix yet
HIGH 8.6
CVE-2026-69558
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
No fix yet
CRITICAL 10.0
CVE-2026-69555
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
No fix yet
HIGH 8.5
CVE-2026-69543
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
No fix yet
HIGH 8.6
CVE-2026-69519
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
No fix yet
HIGH 8.5
CVE-2026-69419
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
No fix yet
CRITICAL 9.6
CVE-2026-69400
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
No fix yet
CRITICAL 9.9
CVE-2026-68789
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…
No fix yet