Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.3
CVE-2026-78154
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/a…
No fix yet
MEDIUM 5.3
CVE-2026-78148
A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggm…
No fix yet
HIGH 7.3
CVE-2026-78147
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml…
No fix yet
MEDIUM 6.3
CVE-2026-78144
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown funct…
No fix yet
HIGH 7.3
CVE-2026-78143
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file reside…
No fix yet
MEDIUM 6.3
CVE-2026-78142
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_…
No fix yet
HIGH 7.4
CVE-2026-78141
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of th…
No fix yet
HIGH 7.5
CVE-2026-9769
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBu…
No fix yet
MEDIUM 6.1
CVE-2026-8630
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements s…
No fix yet
CRITICAL 9.8
CVE-2026-8445
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a…
No fix yet
CRITICAL 9.8
CVE-2026-7808
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s…
No fix yet
MEDIUM 6.1
CVE-2026-77088
justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blan…
No fix yet
MEDIUM 6.1
CVE-2026-74793
justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent pr…
No fix yet
MEDIUM 6.1
CVE-2026-6827
justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve…
No fix yet
MEDIUM 6.1
CVE-2026-5751
justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom Sanitizat…
No fix yet
MEDIUM 6.1
CVE-2026-5389
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre c…
No fix yet
CRITICAL 9.8
CVE-2026-5388
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma…
No fix yet
HIGH 7.5
CVE-2026-4671
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate…
No fix yet
CRITICAL 9.9
CVE-2026-78155
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
No fix yet
MEDIUM 5.4
CVE-2026-78115
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_…
No fix yet
MEDIUM 6.3
CVE-2026-78112
A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.ph…
No fix yet
HIGH 8.5
CVE-2026-10053
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …
No fix yet
HIGH 7.1
CVE-2026-77115
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
No fix yet
HIGH 7.4
CVE-2026-78063
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. Th…
No fix yet
HIGH 7.3
CVE-2026-78062
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the …
No fix yet
MEDIUM 6.3
CVE-2026-78061
A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of …
Patch available
MEDIUM 6.3
CVE-2026-78057
A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the comp…
No fix yet
MEDIUM 6.3
CVE-2026-78056
A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some un…
No fix yet
HIGH 7.8
CVE-2026-78136
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
Patch available
MEDIUM 5.3
CVE-2026-78051
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies…
No fix yet