Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 9.8
CVE-2026-63722
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands b…
No fix yet
HIGH 8.7
CVE-2026-63188
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy…
Patch available
MEDIUM 6.3
CVE-2026-63187
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directl…
Patch available
HIGH 7.5
CVE-2026-62317
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/sr…
Patch available
MEDIUM 5.3
CVE-2026-61711
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom fron…
Patch available
MEDIUM 5.3
CVE-2026-55090
Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtm…
Patch available
CRITICAL 9.9
CVE-2026-55089
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in th…
Patch available
MEDIUM 6.8
CVE-2026-55088
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to …
Patch available
MEDIUM 6.1
CVE-2026-55087
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/h…
Patch available
CRITICAL 9.6
CVE-2026-55085
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a num…
Patch available
MEDIUM 5.1
CVE-2026-54742
Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature…
Patch available
CRITICAL 10.0
CVE-2026-22306
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive informat…
No fix yet
HIGH 7.3
CVE-2026-18871
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware config…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 8.8
CVE-2026-18821
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is a…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 8.8
CVE-2026-17414
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is a…
Power System S1122 \(9824 22a\) Firmware
No fix yet
MEDIUM 6.7
CVE-2026-17097
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 8.4
CVE-2026-17091
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 7.9
CVE-2026-17063
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface be…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 7.3
CVE-2026-17042
IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulner…
Power System S922 \(9009 22g\) Firmware
No fix yet
MEDIUM 6.5
CVE-2026-17028
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerabil…
Power System S1122 \(9824 22a\) Firmware
No fix yet
HIGH 8.2
CVE-2026-16933
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 …
Power System S1122 \(9824 22a\) Firmware
No fix yet
CRITICAL 9.8
CVE-2026-16919
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied …
Aix
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16917
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
Vios
4.1.0.50 / 4.1.1.30+
MEDIUM 6.7
CVE-2026-16914
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16913
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.8
CVE-2026-16911
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.8
CVE-2026-16909
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.6
CVE-2026-16903
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-b…
Vios
4.1.0.50 / 4.1.1.30+
HIGH 8.8
CVE-2026-16901
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16894
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Vios
4.1.0.50 / 4.1.1.30+