Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
HIGH 7.8
CVE-2026-16944
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.8
CVE-2026-16943
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.8
CVE-2026-16937
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.8
CVE-2026-16936
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 7.0
CVE-2026-16935
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU)…
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.8
CVE-2026-16934
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
MEDIUM 6.5
CVE-2026-77641
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() …
No fix yet
MEDIUM 5.3
CVE-2026-77639
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-…
No fix yet
HIGH 8.9
CVE-2026-77638
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the o…
No fix yet
HIGH 8.8
CVE-2026-76023
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the rendere…
Chrome
No fix yet
HIGH 8.8
CVE-2026-76022
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…
Chrome
No fix yet
HIGH 8.8
CVE-2026-76021
Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…
Chrome
No fix yet
HIGH 7.5
CVE-2026-76020
Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HT…
Chrome
No fix yet
HIGH 8.1
CVE-2026-76019
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and le…
Chrome
No fix yet
MEDIUM 5.9
CVE-2026-77587
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last…
No fix yet
HIGH 7.0
CVE-2026-77584
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a …
No fix yet
HIGH 8.8
CVE-2026-76018
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute…
Chrome
No fix yet
HIGH 8.8
CVE-2026-76017
Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via cra…
Chrome
No fix yet
MEDIUM 6.9
CVE-2026-75484
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR,…
Patch available
HIGH 8.7
CVE-2026-74836
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded nu…
Patch available
HIGH 7.7
CVE-2026-73137
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create …
No fix yet
HIGH 8.8
CVE-2026-73040
Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0…
No fix yet
CRITICAL 9.1
CVE-2026-71485
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea…
Patch available
MEDIUM 5.8
CVE-2026-70654
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources an…
Patch available
MEDIUM 6.9
CVE-2026-70651
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick…
Patch available
HIGH 8.4
CVE-2026-69242
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoad…
Patch available
CRITICAL 9.9
CVE-2026-67567
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease cu…
No fix yet
MEDIUM 5.3
CVE-2026-67446
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster befo…
Patch available
MEDIUM 5.3
CVE-2026-67445
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLin…
Patch available
HIGH 7.2
CVE-2026-53804
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execut…
No fix yet