Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.3
CVE-2026-66154
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie…
No fix yet
HIGH 7.8
CVE-2026-66150
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
HIGH 7.8
CVE-2026-66149
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
MEDIUM 6.3
CVE-2026-66148
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…
No fix yet
CRITICAL 9.4
CVE-2026-66147
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…
No fix yet
HIGH 7.1
CVE-2026-63177
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…
No fix yet
MEDIUM 5.4
CVE-2026-63134
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…
No fix yet
MEDIUM 6.5
CVE-2026-63133
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count…
No fix yet
HIGH 8.8
CVE-2026-55676
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…
No fix yet
HIGH 8.2
CVE-2026-19550
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio…
No fix yet
MEDIUM 6.5
CVE-2026-29035
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot…
No fix yet
HIGH 8.4
CVE-2026-18634
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…
No fix yet
HIGH 8.8
CVE-2026-15606
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…
No fix yet
HIGH 8.8
CVE-2026-14863
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod…
No fix yet
MEDIUM 6.3
CVE-2026-71845
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear…
No fix yet
MEDIUM 5.0
CVE-2026-71475
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat…
No fix yet
MEDIUM 6.3
CVE-2026-71474
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens…
No fix yet
MEDIUM 5.3
CVE-2026-71468
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token …
No fix yet
HIGH 7.5
CVE-2026-71467
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ…
No fix yet
MEDIUM 6.1
CVE-2026-66146
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker …
No fix yet
CRITICAL 9.1
CVE-2026-66145
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…
No fix yet
HIGH 8.7
CVE-2026-48813
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralizati…
No fix yet
CRITICAL 10.0
CVE-2026-45618
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…
No fix yet
HIGH 8.1
CVE-2026-18844
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These command…
No fix yet
CRITICAL 9.8
CVE-2026-16230
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun…
No fix yet
HIGH 7.5
CVE-2026-13457
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…
No fix yet
HIGH 7.5
CVE-2026-48809
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of …
No fix yet
HIGH 7.5
CVE-2026-48802
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation o…
No fix yet
HIGH 8.1
CVE-2026-18712
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio…
No fix yet
HIGH 7.1
CVE-2026-18711
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t…
No fix yet