Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
HIGH 8.2
CVE-2026-54682
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-contro…
Patch available
HIGH 7.0
CVE-2026-54134
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and …
Patch available
HIGH 7.8
CVE-2026-54071
BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle …
Patch available
MEDIUM 6.2
CVE-2026-53762
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRY…
Patch available
HIGH 8.4
CVE-2026-77237
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with…
Freertos
No fix yet
HIGH 7.3
CVE-2026-77236
Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap me…
Freertos
No fix yet
HIGH 7.3
CVE-2026-77235
Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-fr…
Freertos
No fix yet
HIGH 8.8
CVE-2026-77234
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel…
Freertos
No fix yet
HIGH 7.5
CVE-2026-71862
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with …
Patch available
MEDIUM 5.9
CVE-2026-71494
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and …
Patch available
MEDIUM 5.9
CVE-2026-71493
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPa…
Patch available
HIGH 8.8
CVE-2026-62677
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a se…
Patch available
HIGH 7.1
CVE-2026-62676
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in om…
Patch available
HIGH 8.8
CVE-2026-62675
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts a…
Patch available
CRITICAL 9.0
CVE-2026-62674
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent chec…
Patch available
HIGH 7.5
CVE-2026-55241
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with …
Patch available
HIGH 7.8
CVE-2026-41451
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_art…
Patch available
HIGH 7.8
CVE-2026-41450
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreac…
Patch available
HIGH 7.8
CVE-2026-41449
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attack…
Patch available
MEDIUM 6.9
CVE-2026-27875
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may all…
No fix yet
HIGH 7.1
CVE-2026-17252
A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-…
No fix yet
HIGH 7.1
CVE-2026-17251
A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An unauthenticated remote attacker can
tr…
No fix yet
HIGH 8.5
CVE-2026-17250
A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controll…
No fix yet
HIGH 7.8
CVE-2026-74583
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_route: fix fastmap use-after-free on filter
The route4 classifie…
Fix unknown
HIGH 7.8
CVE-2026-74582
In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_header_len in non-ring send paths
packet_snd() read…
Fix unknown
CRITICAL 9.8
CVE-2026-74581
In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6 rule result
fib6_rule_suppress() drops a suppr…
Fix unknown
HIGH 8.8
CVE-2026-74580
In the Linux kernel, the following vulnerability has been resolved:
vhost: reset the vring metadata cache on vring reconfiguration
vq->meta_iotlb[]…
Fix unknown
HIGH 8.1
CVE-2026-39909
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attacke…
Patch available
HIGH 7.3
CVE-2026-75933
Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the …
No fix yet
HIGH 8.6
CVE-2026-75932
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and re…
No fix yet