Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.4
CVE-2026-15554
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut…
No fix yet
CRITICAL 9.8
CVE-2026-10579
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…
No fix yet
MEDIUM 6.5
CVE-2026-19391
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th…
No fix yet
HIGH 8.5
CVE-2026-16053
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch…
No fix yet
MEDIUM 5.3
CVE-2026-8158
The Signed Video Framework contained a buffer overflow issue
which could lead the application using this framework to crash. The issue exclusively …
No fix yet
MEDIUM 5.1
CVE-2026-6505
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…
No fix yet
MEDIUM 5.9
CVE-2026-6181
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer…
No fix yet
MEDIUM 5.7
CVE-2026-5304
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …
No fix yet
MEDIUM 5.7
CVE-2026-5303
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…
No fix yet
HIGH 7.2
CVE-2026-4757
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…
No fix yet
MEDIUM 6.5
CVE-2026-14548
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…
No fix yet
CRITICAL 9.1
CVE-2026-19516
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…
No fix yet
CRITICAL 9.8
CVE-2026-19425
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…
No fix yet
MEDIUM 6.4
CVE-2026-16974
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…
No fix yet
HIGH 8.4
CVE-2026-8917
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe…
No fix yet
MEDIUM 6.5
CVE-2026-24330
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…
No fix yet
HIGH 7.5
CVE-2026-19424
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp…
No fix yet
MEDIUM 6.3
CVE-2026-66779
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…
No fix yet
MEDIUM 5.3
CVE-2026-66778
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…
No fix yet
MEDIUM 5.9
CVE-2026-66777
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…
No fix yet
MEDIUM 5.9
CVE-2026-66776
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …
No fix yet
MEDIUM 5.9
CVE-2026-66773
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma…
No fix yet
MEDIUM 6.1
CVE-2026-66771
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …
No fix yet
MEDIUM 6.3
CVE-2026-66770
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…
No fix yet
HIGH 7.9
CVE-2026-66763
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic…
No fix yet
MEDIUM 6.4
CVE-2026-66760
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …
No fix yet
MEDIUM 6.5
CVE-2026-58248
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file…
No fix yet
MEDIUM 5.3
CVE-2026-58247
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi…
No fix yet
HIGH 8.8
CVE-2026-58243
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe…
No fix yet
MEDIUM 5.9
CVE-2026-58238
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…
No fix yet