Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
MEDIUM 6.6
CVE-2026-62381
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate…
No fix yet
MEDIUM 6.3
CVE-2026-62380
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential …
No fix yet
HIGH 7.5
CVE-2026-62243
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on…
No fix yet
MEDIUM 6.6
CVE-2026-62204
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with sa…
No fix yet
HIGH 8.7
CVE-2026-60084
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated…
No fix yet
HIGH 8.8
CVE-2026-59808
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials …
No fix yet
HIGH 7.5
CVE-2026-59256
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity o…
No fix yet
HIGH 7.1
CVE-2026-58003
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authentic…
No fix yet
MEDIUM 6.5
CVE-2026-58002
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json…
No fix yet
MEDIUM 5.7
CVE-2026-58001
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity…
No fix yet
HIGH 7.8
CVE-2026-57998
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option int…
Patch available
MEDIUM 5.4
CVE-2026-57944
AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-…
No fix yet
MEDIUM 5.3
CVE-2026-56380
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve cha…
No fix yet
MEDIUM 6.6
CVE-2026-77988
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration…
No fix yet
HIGH 8.6
CVE-2026-66917
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image ca…
No fix yet
MEDIUM 6.9
CVE-2026-66916
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access cont…
No fix yet
MEDIUM 5.3
CVE-2026-3424
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…
No fix yet
CRITICAL 10.0
CVE-2026-77946
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app…
No fix yet
HIGH 7.4
CVE-2026-77945
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Per…
No fix yet
CRITICAL 9.8
CVE-2026-78003
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including…
No fix yet
CRITICAL 9.3
CVE-2026-12710
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows …
No fix yet
CRITICAL 9.8
CVE-2026-77002
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, …
No fix yet
CRITICAL 9.8
CVE-2026-77001
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no…
No fix yet
CRITICAL 9.8
CVE-2026-77000
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before…
No fix yet
HIGH 8.1
CVE-2026-76793
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matchin…
No fix yet
HIGH 8.8
CVE-2026-76789
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request han…
No fix yet
MEDIUM 6.6
CVE-2026-19222
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing …
No fix yet
HIGH 7.2
CVE-2026-19221
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator …
No fix yet
MEDIUM 6.8
CVE-2026-19093
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor…
No fix yet
HIGH 8.1
CVE-2026-18052
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent…
No fix yet