Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-18651
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t…
Directory Server
No fix yet
CRITICAL 9.1
CVE-2026-18248
@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications…
No fix yet
MEDIUM 6.2
CVE-2026-15430
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …
No fix yet
HIGH 7.8
CVE-2026-67609
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows a…
No fix yet
HIGH 7.0
CVE-2026-69097
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives t…
No fix yet
HIGH 7.5
CVE-2026-69095
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that…
No fix yet
MEDIUM 6.5
CVE-2026-69092
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messag…
No fix yet
HIGH 7.5
CVE-2026-69091
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logi…
No fix yet
HIGH 8.1
CVE-2026-69088
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives bec…
No fix yet
MEDIUM 6.5
CVE-2026-69087
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action eva…
No fix yet
HIGH 7.7
CVE-2026-69086
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to constr…
No fix yet
CRITICAL 10.0
CVE-2026-69085
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is …
No fix yet
CRITICAL 10.0
CVE-2026-69084
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr…
No fix yet
CRITICAL 10.0
CVE-2026-69083
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and…
No fix yet
HIGH 8.6
CVE-2026-68587
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get…
No fix yet
HIGH 8.6
CVE-2026-68586
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and…
No fix yet
MEDIUM 5.8
CVE-2026-68585
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata…
No fix yet
HIGH 8.6
CVE-2026-68584
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM,…
No fix yet
HIGH 7.2
CVE-2026-67608
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_au…
No fix yet
CRITICAL 9.8
CVE-2026-64827
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.…
No fix yet
HIGH 7.8
CVE-2026-18642
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.
Thi…
No fix yet
CRITICAL 9.8
CVE-2026-18601
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon…
No fix yet
HIGH 8.8
CVE-2026-18600
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr…
No fix yet
MEDIUM 6.5
CVE-2026-56609
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TL…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56608
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…
Icontrol
No fix yet
CRITICAL 9.8
CVE-2026-2346
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affe…
No fix yet
HIGH 8.0
CVE-2026-18599
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/lo…
No fix yet
HIGH 8.8
CVE-2026-18598
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-h…
No fix yet
CRITICAL 9.3
CVE-2026-18574
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una…
No fix yet
MEDIUM 5.5
CVE-2026-68742
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining p…
Openshift Container Platform
No fix yet