Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2026-18709
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa…
No fix yet
MEDIUM 6.4
CVE-2026-18708
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe…
No fix yet
MEDIUM 6.6
CVE-2026-18706
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management command…
No fix yet
MEDIUM 6.5
CVE-2026-18705
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a …
No fix yet
MEDIUM 6.5
CVE-2026-18704
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co…
No fix yet
MEDIUM 6.4
CVE-2026-18702
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe…
No fix yet
MEDIUM 6.5
CVE-2026-18701
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpect…
No fix yet
MEDIUM 6.5
CVE-2026-18700
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used …
No fix yet
MEDIUM 6.5
CVE-2026-18699
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unex…
No fix yet
MEDIUM 5.4
CVE-2026-18698
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
HIGH 7.5
CVE-2026-18697
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly …
No fix yet
MEDIUM 6.5
CVE-2026-18696
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti…
No fix yet
MEDIUM 6.5
CVE-2026-18695
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user …
No fix yet
HIGH 7.1
CVE-2026-18694
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry …
No fix yet
HIGH 7.6
CVE-2026-18693
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data str…
No fix yet
HIGH 8.8
CVE-2026-18692
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref…
No fix yet
HIGH 8.8
CVE-2026-18691
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…
No fix yet
HIGH 8.1
CVE-2026-18690
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
HIGH 7.1
CVE-2026-18688
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially…
No fix yet
HIGH 7.1
CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection…
No fix yet
HIGH 8.8
CVE-2026-15426
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by…
No fix yet
HIGH 7.7
CVE-2026-73218
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do…
No fix yet
HIGH 7.7
CVE-2026-73217
Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to repla…
No fix yet
CRITICAL 10.0
CVE-2026-71398
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
CRITICAL 9.1
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…
No fix yet
HIGH 8.2
CVE-2026-48771
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien…
No fix yet
HIGH 7.5
CVE-2026-48416
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
No fix yet
HIGH 7.6
CVE-2026-48415
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker coul…
No fix yet
HIGH 7.7
CVE-2026-48414
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
No fix yet
HIGH 8.7
CVE-2026-48413
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
No fix yet