Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 9.8
CVE-2025-15689
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
No fix yet
CRITICAL 9.3
CVE-2025-15688
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
No fix yet
HIGH 8.1
CVE-2025-15637
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
No fix yet
MEDIUM 5.0
CVE-2026-77067
The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file im…
Patch available
MEDIUM 5.0
CVE-2026-77066
The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig(…
Patch available
MEDIUM 6.5
CVE-2026-73196
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key…
Enterprise Linux
4.13.3+
MEDIUM 6.9
CVE-2026-77026
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforc…
No fix yet
MEDIUM 6.5
CVE-2026-73199
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending …
No fix yet
HIGH 7.5
CVE-2026-73198
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitr…
Enterprise Linux
4.13.3+
HIGH 7.5
CVE-2026-73197
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/m…
Enterprise Linux
4.13.3+
CRITICAL 9.1
CVE-2026-13097
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se…
Enterprise Linux
No fix yet
HIGH 8.1
CVE-2026-11861
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti…
Enterprise Linux
4.13.3+
HIGH 7.8
CVE-2026-18917
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla…
No fix yet
MEDIUM 5.3
CVE-2026-77014
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt…
No fix yet
MEDIUM 6.9
CVE-2026-76610
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una…
No fix yet
HIGH 7.5
CVE-2026-14952
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f…
No fix yet
HIGH 8.0
CVE-2026-14951
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
No fix yet
CRITICAL 9.8
CVE-2026-14950
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…
No fix yet
MEDIUM 6.5
CVE-2026-14949
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr…
No fix yet
HIGH 8.8
CVE-2026-14948
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl…
No fix yet
HIGH 7.2
CVE-2026-14947
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra…
No fix yet
HIGH 7.2
CVE-2026-14946
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio…
No fix yet
MEDIUM 5.3
CVE-2026-76569
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
No fix yet
MEDIUM 5.3
CVE-2026-76565
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
No fix yet
HIGH 8.6
CVE-2026-76564
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
No fix yet
HIGH 8.6
CVE-2026-75948
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and …
No fix yet
HIGH 8.6
CVE-2025-14601
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system…
No fix yet
MEDIUM 6.1
CVE-2026-71368
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation…
No fix yet
HIGH 7.1
CVE-2026-14163
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn…
No fix yet
MEDIUM 5.3
CVE-2025-14602
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac…
No fix yet