Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
HIGH 8.5
CVE-2026-69419
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
No fix yet
CRITICAL 9.6
CVE-2026-69400
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
Azure Logic Apps
No fix yet
CRITICAL 9.9
CVE-2026-68789
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…
Azure Sql Database
No fix yet
CRITICAL 9.9
CVE-2026-68782
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…
Azure Sql Database
No fix yet
MEDIUM 6.5
CVE-2026-67448
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw Reques…
Patch available
MEDIUM 5.3
CVE-2026-67447
Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.…
Patch available
HIGH 7.5
CVE-2026-66800
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
Azure Data Factory
No fix yet
CRITICAL 9.1
CVE-2026-66309
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Azure Sql Database
No fix yet
CRITICAL 10.0
CVE-2026-65816
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Web Apps
No fix yet
CRITICAL 10.0
CVE-2026-65801
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Exchange Online
No fix yet
CRITICAL 10.0
CVE-2026-65770
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthori…
Azure Managed Instance For Apache Cassandra
No fix yet
CRITICAL 9.9
CVE-2026-63509
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 9.8
CVE-2026-62834
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Azure Data Factory
No fix yet
MEDIUM 6.8
CVE-2026-55894
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value…
Patch available
HIGH 7.3
CVE-2026-55893
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFM…
Patch available
CRITICAL 9.4
CVE-2026-55769
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened …
Patch available
HIGH 8.5
CVE-2026-55765
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedde…
Patch available
MEDIUM 5.4
CVE-2026-55491
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/pla…
Patch available
MEDIUM 5.5
CVE-2026-55015
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
No fix yet
HIGH 7.1
CVE-2026-55013
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
No fix yet
MEDIUM 6.5
CVE-2026-54509
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns th…
Patch available
MEDIUM 5.3
CVE-2026-54508
TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() an…
Patch available
MEDIUM 5.5
CVE-2026-54389
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra proc…
No fix yet
MEDIUM 6.9
CVE-2026-50192
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub c…
Patch available
HIGH 7.3
CVE-2026-49436
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URL…
Patch available
MEDIUM 5.9
CVE-2026-49244
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a brow…
Patch available
HIGH 7.5
CVE-2026-49217
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any u…
No fix yet
HIGH 8.5
CVE-2026-46682
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingI…
Patch available
HIGH 7.1
CVE-2026-46355
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebu…
Patch available
HIGH 7.8
CVE-2026-19783
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafte…
Vios
Fix available