Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2026-53528
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authen…
No fix yet
HIGH 8.8
CVE-2026-53527
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user…
No fix yet
MEDIUM 5.7
CVE-2026-53509
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and…
No fix yet
MEDIUM 5.3
CVE-2026-53497
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the o…
No fix yet
CRITICAL 9.1
CVE-2026-49849
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr…
Patch available
MEDIUM 6.3
CVE-2026-43980
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, …
Patch available
MEDIUM 6.5
CVE-2026-34836
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for d…
Patch available
HIGH 8.6
CVE-2026-34741
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbi…
Patch available
HIGH 8.8
CVE-2026-33240
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign…
Patch available
HIGH 8.8
CVE-2026-31936
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operat…
Patch available
HIGH 8.7
CVE-2026-77811
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions t…
No fix yet
CRITICAL 9.3
CVE-2026-77415
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn…
Patch available
CRITICAL 9.3
CVE-2026-77414
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw…
Patch available
CRITICAL 9.3
CVE-2026-77413
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn…
Patch available
HIGH 8.7
CVE-2026-77354
kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder…
Patch available
MEDIUM 6.5
CVE-2026-77220
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buff…
Patch available
HIGH 7.1
CVE-2026-77219
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplyi…
Patch available
HIGH 7.5
CVE-2026-76905
kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_erro…
Patch available
CRITICAL 9.8
CVE-2026-76904
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,…
Patch available
MEDIUM 6.1
CVE-2026-69236
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject…
No fix yet
MEDIUM 6.1
CVE-2026-69235
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…
No fix yet
MEDIUM 6.1
CVE-2026-69234
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated a…
No fix yet
MEDIUM 5.5
CVE-2026-69233
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…
No fix yet
MEDIUM 5.5
CVE-2026-69232
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…
No fix yet
MEDIUM 5.5
CVE-2026-69231
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…
No fix yet
MEDIUM 5.5
CVE-2026-69230
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…
No fix yet
MEDIUM 5.4
CVE-2026-69229
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arb…
No fix yet
MEDIUM 5.3
CVE-2026-69228
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker t…
No fix yet
MEDIUM 5.9
CVE-2026-69225
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenti…
No fix yet
MEDIUM 5.9
CVE-2026-69224
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstan…
No fix yet