Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
HIGH 8.6
CVE-2026-76613
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-lev…
No fix yet
HIGH 8.6
CVE-2026-76612
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user su…
No fix yet
MEDIUM 6.9
CVE-2026-76611
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
No fix yet
HIGH 7.0
CVE-2026-75115
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is…
No fix yet
MEDIUM 6.8
CVE-2026-59654
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects diffe…
No fix yet
CRITICAL 9.1
CVE-2026-77776
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/p…
Patch available
HIGH 8.6
CVE-2026-77775
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in head…
Patch available
HIGH 8.7
CVE-2026-77759
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero
Flow CRM 5.0.0 through 5.3.5 allows an authenticated user …
Patch available
MEDIUM 6.5
CVE-2026-59318
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is…
No fix yet
HIGH 7.5
CVE-2026-59279
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default …
No fix yet
MEDIUM 6.5
CVE-2026-19848
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allow…
No fix yet
MEDIUM 5.3
CVE-2026-17559
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass gl…
No fix yet
MEDIUM 5.3
CVE-2026-16650
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, …
No fix yet
MEDIUM 5.3
CVE-2026-15150
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured …
No fix yet
MEDIUM 6.5
CVE-2026-77769
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboar…
Patch available
MEDIUM 6.5
CVE-2026-77768
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAc…
Patch available
HIGH 7.5
CVE-2026-77767
Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role,…
Patch available
MEDIUM 6.5
CVE-2026-77763
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from …
Patch available
MEDIUM 6.3
CVE-2026-77761
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into t…
Patch available
MEDIUM 5.4
CVE-2026-77686
A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handl…
Patch available
CRITICAL 9.9
CVE-2026-77683
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method…
No fix yet
CRITICAL 9.1
CVE-2026-77086
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to …
No fix yet
MEDIUM 5.9
CVE-2026-59296
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-…
No fix yet
MEDIUM 6.9
CVE-2026-15576
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate …
No fix yet
HIGH 7.3
CVE-2026-14208
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), …
No fix yet
HIGH 8.7
CVE-2026-77755
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents.
The STIX import code u…
Patch available
HIGH 8.8
CVE-2026-77751
A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export.
MISP object nam…
Patch available
MEDIUM 6.3
CVE-2026-77681
A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/upda…
No fix yet
MEDIUM 5.3
CVE-2026-59323
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded ob…
No fix yet
HIGH 7.5
CVE-2026-47827
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vul…
No fix yet