Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-64558
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Check length in pkey_pckmo handler implementation
Explicitly check t…
No fix yet
CRITICAL 9.1
CVE-2026-51992
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …
Mitigation only
MEDIUM 5.6
CVE-2026-18257
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root i…
No fix yet
HIGH 7.2
CVE-2026-18255
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a membe…
No fix yet
HIGH 7.5
CVE-2025-60931
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attacker…
No fix yet
MEDIUM 5.3
CVE-2026-67193
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current …
No fix yet
HIGH 8.1
CVE-2026-67192
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt sta…
No fix yet
CRITICAL 9.8
CVE-2026-67191
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write…
No fix yet
HIGH 7.1
CVE-2026-16543
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w…
No fix yet
HIGH 7.1
CVE-2026-15228
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration…
No fix yet
MEDIUM 5.3
CVE-2026-66724
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoi…
No fix yet
HIGH 7.0
CVE-2026-66723
MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify…
No fix yet
HIGH 8.0
CVE-2026-12703
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a co…
No fix yet
CRITICAL 9.4
CVE-2026-9177
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of the Axway SecureTransport product in vers…
No fix yet
MEDIUM 6.5
CVE-2026-16751
Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured…
No fix yet
HIGH 7.1
CVE-2026-50641
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database
This issue was fixed in version 6.8.0.0, users were …
No fix yet
MEDIUM 5.1
CVE-2026-33385
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip…
No fix yet
HIGH 8.7
CVE-2026-14354
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po…
No fix yet
HIGH 8.4
CVE-2026-12927
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file…
No fix yet
CRITICAL 9.3
CVE-2026-0667
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of …
No fix yet
HIGH 8.8
CVE-2026-14270
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in…
No fix yet
MEDIUM 6.4
CVE-2026-8791
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to…
No fix yet
MEDIUM 6.4
CVE-2026-7436
The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes…
No fix yet
MEDIUM 6.5
CVE-2026-5060
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…
No fix yet
MEDIUM 6.8
CVE-2026-56389
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var…
No fix yet
MEDIUM 5.3
CVE-2026-4604
The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_…
No fix yet
HIGH 7.8
CVE-2026-18220
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() funct…
No fix yet
HIGH 7.2
CVE-2026-16655
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…
No fix yet
HIGH 7.2
CVE-2026-16597
The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billin…
No fix yet
CRITICAL 9.8
CVE-2026-14900
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to…
No fix yet