Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.0
CVE-2026-20475
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac…
Mt8910 Firmware
No fix yet
MEDIUM 6.0
CVE-2026-20474
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious acto…
Mt6991 Firmware
No fix yet
MEDIUM 6.0
CVE-2026-20473
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…
Mt6991 Firmware
No fix yet
MEDIUM 6.2
CVE-2026-20470
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…
No fix yet
MEDIUM 6.0
CVE-2026-20469
In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a m…
No fix yet
MEDIUM 6.0
CVE-2026-20468
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious acto…
No fix yet
MEDIUM 6.0
CVE-2026-20467
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious…
No fix yet
MEDIUM 6.1
CVE-2026-20466
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attac…
No fix yet
HIGH 8.1
CVE-2026-20465
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of…
No fix yet
MEDIUM 6.5
CVE-2026-20464
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious…
No fix yet
HIGH 7.1
CVE-2026-65875
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malici…
No fix yet
HIGH 7.5
CVE-2026-3245
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
No fix yet
MEDIUM 5.4
CVE-2026-68583
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us…
No fix yet
MEDIUM 6.5
CVE-2026-68582
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1…
No fix yet
HIGH 7.5
CVE-2026-68580
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL …
No fix yet
HIGH 7.5
CVE-2026-68578
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently …
No fix yet
HIGH 7.5
CVE-2026-67357
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluste…
No fix yet
HIGH 8.8
CVE-2026-67356
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe…
No fix yet
MEDIUM 5.9
CVE-2025-71401
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An …
No fix yet
HIGH 7.1
CVE-2025-71400
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth…
No fix yet
MEDIUM 6.4
CVE-2026-12231
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v…
No fix yet
MEDIUM 6.5
CVE-2026-18573
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18572
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…
Build Of Keycloak
No fix yet
HIGH 7.2
CVE-2026-18571
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-18570
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-16292
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing…
No fix yet
HIGH 7.5
CVE-2026-16540
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec…
No fix yet
HIGH 7.5
CVE-2026-16285
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a…
No fix yet
CRITICAL 9.8
CVE-2026-16256
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…
No fix yet
HIGH 7.5
CVE-2026-16261
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss…
No fix yet