Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.6
CVE-2026-58047
HTTP Smuggling in cPanel allows potential leak of credentials.
No fix yet
MEDIUM 5.9
CVE-2026-67607
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftp…
No fix yet
MEDIUM 5.3
CVE-2026-56568
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56571
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56570
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…
Icontrol
No fix yet
MEDIUM 5.1
CVE-2026-56567
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to…
No fix yet
HIGH 8.2
CVE-2026-18141
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa…
No fix yet
CRITICAL 9.8
CVE-2026-16504
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HT…
Mitigation only
CRITICAL 9.1
CVE-2026-16503
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default…
No fix yet
HIGH 7.5
CVE-2026-18446
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash ba…
No fix yet
MEDIUM 5.3
CVE-2026-28145
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State.
This issue affects Ma…
No fix yet
HIGH 7.5
CVE-2026-18358
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the inco…
No fix yet
CRITICAL 9.8
CVE-2026-17561
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign…
No fix yet
MEDIUM 5.3
CVE-2026-15227
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" per…
No fix yet
MEDIUM 5.1
CVE-2026-46594
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a speci…
No fix yet
HIGH 8.6
CVE-2026-46593
A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminP…
No fix yet
MEDIUM 6.9
CVE-2025-67651
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSit…
No fix yet
HIGH 8.6
CVE-2025-67650
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an aut…
No fix yet
CRITICAL 9.3
CVE-2025-67649
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into paramet…
No fix yet
MEDIUM 5.3
CVE-2026-17567
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…
No fix yet
HIGH 7.2
CVE-2026-16843
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid crede…
No fix yet
MEDIUM 5.3
CVE-2026-18437
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability c…
No fix yet
MEDIUM 5.3
CVE-2026-18436
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore RES…
No fix yet
HIGH 7.5
CVE-2026-15722
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c…
Directory Server
No fix yet
HIGH 7.5
CVE-2026-11770
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c…
Directory Server
No fix yet
HIGH 8.5
CVE-2026-10079
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identit…
No fix yet
HIGH 8.1
CVE-2026-65313
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because…
No fix yet
MEDIUM 5.3
CVE-2026-65311
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's …
No fix yet
HIGH 7.5
CVE-2026-65310
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any a…
No fix yet
MEDIUM 5.4
CVE-2026-18218
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe…
Build Of Keycloak
No fix yet