Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
MEDIUM 6.9
CVE-2026-77710
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import.
The STIX imp…
Patch available
HIGH 8.1
CVE-2026-68745
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a…
No fix yet
HIGH 7.2
CVE-2026-66722
Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack.
A Domain Admin can crea…
No fix yet
MEDIUM 5.8
CVE-2026-74866
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur…
No fix yet
MEDIUM 5.4
CVE-2026-66797
Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure.
The addAnnotation and listA…
No fix yet
HIGH 8.8
CVE-2026-63046
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex…
No fix yet
CRITICAL 9.1
CVE-2026-62440
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cl…
Fix unknown
CRITICAL 9.1
CVE-2026-61398
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality.
This issue affect…
Fix unknown
HIGH 7.5
CVE-2026-61397
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integra…
Fix unknown
HIGH 8.8
CVE-2026-61400
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func…
No fix yet
HIGH 7.5
CVE-2026-59780
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP provide…
Fix unknown
HIGH 7.5
CVE-2026-59657
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database.
This issue affects Apache Cloud…
Fix unknown
HIGH 7.5
CVE-2026-59655
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth provi…
Fix unknown
CRITICAL 9.1
CVE-2026-59085
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.
This issue affect…
Fix unknown
HIGH 7.5
CVE-2026-50222
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs.
Seve…
Fix unknown
HIGH 8.8
CVE-2026-59799
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication …
No fix yet
HIGH 8.8
CVE-2026-50112
SSRF via Metalink Mirror URL Resolution:
An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing…
No fix yet
CRITICAL 9.8
CVE-2026-77264
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas…
No fix yet
MEDIUM 5.3
CVE-2026-19441
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
This issue affects Rush: thr…
No fix yet
HIGH 7.5
CVE-2026-16323
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass…
No fix yet
HIGH 7.2
CVE-2026-75796
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing …
No fix yet
HIGH 8.1
CVE-2026-18781
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after …
No fix yet
MEDIUM 5.3
CVE-2026-16962
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret…
No fix yet
MEDIUM 6.8
CVE-2026-16959
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its …
No fix yet
HIGH 7.2
CVE-2026-16576
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some…
No fix yet
MEDIUM 5.3
CVE-2026-16575
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission …
No fix yet
MEDIUM 6.8
CVE-2026-14601
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen…
No fix yet
MEDIUM 5.3
CVE-2026-13736
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,…
No fix yet
MEDIUM 5.4
CVE-2025-15671
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr…
No fix yet
HIGH 7.2
CVE-2026-18409
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version…
No fix yet