Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-77014
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt…
No fix yet
MEDIUM 6.9
CVE-2026-76610
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una…
No fix yet
HIGH 7.5
CVE-2026-14952
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f…
No fix yet
HIGH 8.0
CVE-2026-14951
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
No fix yet
CRITICAL 9.8
CVE-2026-14950
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…
No fix yet
MEDIUM 6.5
CVE-2026-14949
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr…
No fix yet
HIGH 8.8
CVE-2026-14948
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl…
No fix yet
HIGH 7.2
CVE-2026-14947
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra…
No fix yet
HIGH 7.2
CVE-2026-14946
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio…
No fix yet
MEDIUM 5.3
CVE-2026-76569
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
No fix yet
MEDIUM 5.3
CVE-2026-76565
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
No fix yet
HIGH 8.6
CVE-2026-76564
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
No fix yet
HIGH 8.6
CVE-2026-75948
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and …
No fix yet
HIGH 8.6
CVE-2025-14601
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system…
No fix yet
MEDIUM 6.1
CVE-2026-71368
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation…
No fix yet
HIGH 7.1
CVE-2026-14163
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn…
No fix yet
MEDIUM 5.3
CVE-2025-14602
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac…
No fix yet
HIGH 7.5
CVE-2026-75963
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_…
No fix yet
CRITICAL 9.8
CVE-2026-75860
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r…
No fix yet
MEDIUM 6.8
CVE-2026-74992
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does …
No fix yet
MEDIUM 6.8
CVE-2026-19697
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …
No fix yet
MEDIUM 6.8
CVE-2026-19615
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allo…
No fix yet
MEDIUM 5.3
CVE-2026-17153
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the…
No fix yet
HIGH 7.2
CVE-2026-15049
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does…
No fix yet
MEDIUM 6.6
CVE-2026-13405
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is…
No fix yet
MEDIUM 5.9
CVE-2026-76956
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnera…
Patch available
HIGH 7.8
CVE-2026-19582
In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buff…
No fix yet
MEDIUM 6.3
CVE-2026-76800
A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Exe…
No fix yet
MEDIUM 5.3
CVE-2026-76799
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/log…
No fix yet
HIGH 7.3
CVE-2026-76795
A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. T…
Patch available