Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.2
CVE-2026-56657
Gitea SSH Key Parser Denial of Service
No fix yet
MEDIUM 5.4
CVE-2026-55986
Email Management API Bypasses ManageCredentials Feature Restrictions
No fix yet
CRITICAL 9.1
CVE-2026-55982
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
No fix yet
HIGH 7.5
CVE-2026-54481
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
No fix yet
HIGH 8.7
CVE-2026-55402
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an ‘in the middle’
position c…
No fix yet
MEDIUM 6.5
CVE-2026-42931
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
No fix yet
MEDIUM 6.1
CVE-2026-73671
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the u…
No fix yet
HIGH 7.2
CVE-2026-73670
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a…
No fix yet
MEDIUM 6.3
CVE-2026-73576
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumen…
No fix yet
MEDIUM 6.1
CVE-2026-73572
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insuff…
No fix yet
HIGH 8.9
CVE-2026-73570 KEV
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP…
Zimbra Collaboration Suite
No fix yet
CRITICAL 9.8
CVE-2026-73533
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned upda…
No fix yet
CRITICAL 9.8
CVE-2026-73532
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat…
No fix yet
HIGH 8.1
CVE-2026-73515
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplyin…
No fix yet
MEDIUM 6.9
CVE-2026-55401
CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an …
No fix yet
MEDIUM 6.0
CVE-2026-55400
CVE-2026-55400 is an integer underflow in Secure Access servers prior to
version 14.57. Attackers with an authenticated session can send
specially …
No fix yet
HIGH 7.3
CVE-2026-19710
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file…
No fix yet
HIGH 7.5
CVE-2026-70464
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection …
No fix yet
HIGH 8.1
CVE-2026-70463
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp…
No fix yet
MEDIUM 6.5
CVE-2026-70462
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disa…
No fix yet
HIGH 8.2
CVE-2026-70461
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-control…
No fix yet
HIGH 8.1
CVE-2026-70460
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with…
No fix yet
MEDIUM 5.3
CVE-2026-70459
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daem…
No fix yet
HIGH 8.2
CVE-2026-70458
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on…
No fix yet
MEDIUM 6.5
CVE-2026-70457
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a…
No fix yet
HIGH 8.2
CVE-2026-70456
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent…
No fix yet
HIGH 7.5
CVE-2026-70455
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt sh…
No fix yet
HIGH 8.0
CVE-2026-70454
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on…
No fix yet
HIGH 7.5
CVE-2026-70453
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of …
No fix yet
HIGH 7.4
CVE-2026-70452
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS …
No fix yet