Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-77641
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() …
No fix yet
MEDIUM 5.3
CVE-2026-77639
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-…
No fix yet
HIGH 8.9
CVE-2026-77638
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the o…
No fix yet
HIGH 8.8
CVE-2026-76023
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the rendere…
No fix yet
HIGH 8.8
CVE-2026-76022
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…
No fix yet
HIGH 8.8
CVE-2026-76021
Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…
No fix yet
HIGH 7.5
CVE-2026-76020
Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HT…
No fix yet
HIGH 8.1
CVE-2026-76019
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and le…
No fix yet
MEDIUM 5.9
CVE-2026-77587
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last…
No fix yet
HIGH 7.0
CVE-2026-77584
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a …
No fix yet
HIGH 8.8
CVE-2026-76018
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute…
No fix yet
HIGH 8.8
CVE-2026-76017
Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via cra…
No fix yet
MEDIUM 6.9
CVE-2026-75484
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR,…
Patch available
HIGH 8.7
CVE-2026-74836
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded nu…
Patch available
HIGH 7.7
CVE-2026-73137
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create …
No fix yet
HIGH 8.8
CVE-2026-73040
Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0…
No fix yet
CRITICAL 9.1
CVE-2026-71485
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea…
Patch available
MEDIUM 5.8
CVE-2026-70654
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources an…
Patch available
MEDIUM 6.9
CVE-2026-70651
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick…
Patch available
HIGH 8.4
CVE-2026-69242
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoad…
Patch available
CRITICAL 9.9
CVE-2026-67567
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease cu…
No fix yet
MEDIUM 5.3
CVE-2026-67446
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster befo…
Patch available
MEDIUM 5.3
CVE-2026-67445
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLin…
Patch available
HIGH 7.2
CVE-2026-53804
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execut…
No fix yet
MEDIUM 6.9
CVE-2026-19755
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath value…
No fix yet
HIGH 8.8
CVE-2026-18420
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arb…
No fix yet
MEDIUM 6.5
CVE-2026-75910
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an au…
No fix yet
MEDIUM 5.8
CVE-2026-72861
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-iss…
No fix yet
MEDIUM 6.0
CVE-2026-9033
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, inc…
No fix yet
CRITICAL 9.9
CVE-2026-77148
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_…
No fix yet