Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
MEDIUM 6.5
CVE-2026-61842
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration obj…
Patch available
MEDIUM 6.5
CVE-2026-61690
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives t…
Patch available
MEDIUM 5.3
CVE-2026-53654
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and…
Patch available
HIGH 7.5
CVE-2026-46343
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.en…
Patch available
MEDIUM 5.3
CVE-2026-44254
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMe…
Patch available
HIGH 7.7
CVE-2026-44252
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-pri…
Patch available
MEDIUM 6.3
CVE-2026-19672
The tarfile module's tar and data
extraction filters created directories outside the destination for
members whose name leaves the destination and …
Patch available
HIGH 7.2
CVE-2026-18430
HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete anothe…
Patch available
HIGH 7.7
CVE-2026-16819
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-o…
Vios
4.1.0.50 / 4.1.1.30+
MEDIUM 5.1
CVE-2026-76203
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer
in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenti…
Patch available
HIGH 8.7
CVE-2026-75956
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly t…
No fix yet
MEDIUM 5.1
CVE-2026-75955
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped …
No fix yet
CRITICAL 9.3
CVE-2026-75954
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated int…
No fix yet
MEDIUM 6.9
CVE-2026-75951
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
No fix yet
MEDIUM 6.9
CVE-2026-75950
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attac…
No fix yet
CRITICAL 10.0
CVE-2026-75949
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a clien…
No fix yet
HIGH 8.8
CVE-2026-71961
Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrar…
No fix yet
CRITICAL 9.1
CVE-2026-71960
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authenticat…
No fix yet
HIGH 8.8
CVE-2026-71176
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
Openmanage Enterprise
4.7.0+
MEDIUM 6.5
CVE-2026-67268
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged …
Command Update
5.7.1+
MEDIUM 5.5
CVE-2026-67267
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerabili…
Command Update
5.7.1+
MEDIUM 5.5
CVE-2026-67266
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access cou…
Command Update
5.7.1+
HIGH 8.8
CVE-2026-58565
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …
Command Update
5.7.1+
HIGH 7.8
CVE-2026-58564
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce…
Command Update
5.7.1+
HIGH 7.3
CVE-2026-58562
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …
Command Update
5.7.1+
HIGH 7.3
CVE-2026-56797
Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with…
Command Update
5.7.1+
MEDIUM 6.6
CVE-2026-56796
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low pr…
Command Update
5.7.1+
MEDIUM 5.4
CVE-2026-54793
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')…
Openmanage Enterprise
4.7.0+
HIGH 7.8
CVE-2026-53477
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac…
Command Update
5.7.1+
MEDIUM 5.3
CVE-2026-53452
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the…
Patch available