Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.6
CVE-2026-12721
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, al…
No fix yet
HIGH 7.5
CVE-2026-12720
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca…
No fix yet
MEDIUM 5.4
CVE-2026-12697
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag…
No fix yet
HIGH 8.1
CVE-2026-12695
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instea…
No fix yet
HIGH 8.1
CVE-2026-12251
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist…
No fix yet
HIGH 7.1
CVE-2026-55502
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even …
No fix yet
MEDIUM 5.3
CVE-2026-43833
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
HIGH 7.5
CVE-2026-43832
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
HIGH 7.5
CVE-2026-43831
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
CRITICAL 9.8
CVE-2026-43830
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
HIGH 7.5
CVE-2026-43829
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
HIGH 7.1
CVE-2026-6890
A use of default credentials vulnerability in the Advantech ECU-1251D allows a remote attacker to gain unauthorised access to the device via SSH usin…
No fix yet
MEDIUM 6.9
CVE-2026-6889
A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address o…
No fix yet
MEDIUM 6.5
CVE-2026-66720
The GOOSE subscriber component improperly validates the UTC timestamp
field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
multicast…
No fix yet
CRITICAL 9.3
CVE-2026-66421
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript …
No fix yet
MEDIUM 6.5
CVE-2026-66369
The GOOSE parser contains an off-by-one boundary-handling flaw that can
be triggered by a single unauthenticated Layer-2 multicast frame on the
pro…
No fix yet
MEDIUM 6.5
CVE-2026-66364
The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process…
No fix yet
HIGH 7.5
CVE-2026-66360
The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
pro…
No fix yet
MEDIUM 6.5
CVE-2026-66349
The MMS server connection handler contains a flaw in its processing of
BER-encoded request data. When an MMS confirmed request PDU containing
an ex…
No fix yet
MEDIUM 6.5
CVE-2026-65421
The MMS BER decoder contains a flaw in decoding fixed-width BER fields
(boolean/integer): an attacker-supplied length value is not validated,
causi…
No fix yet
MEDIUM 6.5
CVE-2026-63550
The MMS BER decoder contains a boundary-handling flaw in the processing
of certain fields within confirmed-request messages. When a crafted
BER-enc…
No fix yet
MEDIUM 6.5
CVE-2026-63033
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to …
No fix yet
MEDIUM 6.5
CVE-2026-61893
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past t…
No fix yet
MEDIUM 6.5
CVE-2026-56758
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
connection establishment. When parsing certain fields within the
calling A…
No fix yet
MEDIUM 5.5
CVE-2026-68563
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data`…
No fix yet
MEDIUM 6.2
CVE-2026-68562
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate…
No fix yet
MEDIUM 5.7
CVE-2026-5846
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticat…
No fix yet
CRITICAL 9.8
CVE-2026-38709
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer…
No fix yet
HIGH 7.5
CVE-2026-18064
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
derefer…
No fix yet
HIGH 8.8
CVE-2026-12562
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the em…
No fix yet