Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2026-66374
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
No fix yet
MEDIUM 6.5
CVE-2026-66339
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header…
No fix yet
MEDIUM 5.4
CVE-2026-66338
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs vio…
No fix yet
MEDIUM 6.5
CVE-2026-66337
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when …
No fix yet
HIGH 8.8
CVE-2026-61892
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
No fix yet
MEDIUM 6.5
CVE-2026-61886
Weintek cMT3092X HMI stores user account passwords in plaintext.
No fix yet
MEDIUM 6.5
CVE-2026-60135
An attacker can modify data that should be restricted to read‑only access.
No fix yet
HIGH 8.8
CVE-2026-60134
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
No fix yet
CRITICAL 9.8
CVE-2026-61884
The web management interface of Tycon Systems TPDIN-Monitor-WEB2
does not perform server-side validation of credentials during the login process. B…
No fix yet
HIGH 7.5
CVE-2026-62835
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Azure Portal
No fix yet
HIGH 8.1
CVE-2026-54342
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p…
No fix yet
CRITICAL 9.1
CVE-2026-48021
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…
No fix yet
HIGH 8.5
CVE-2026-17107
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-eng…
No fix yet
HIGH 7.2
CVE-2026-65711
sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands …
No fix yet
HIGH 7.1
CVE-2026-65710
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag…
No fix yet
HIGH 8.3
CVE-2026-65709
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume…
No fix yet
HIGH 8.1
CVE-2026-65708
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi…
No fix yet
MEDIUM 6.5
CVE-2026-65707
Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by …
No fix yet
HIGH 7.2
CVE-2026-65693
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary O…
No fix yet
HIGH 8.1
CVE-2026-8789
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver…
No fix yet
MEDIUM 6.1
CVE-2026-8308
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W…
No fix yet
CRITICAL 9.8
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Azure App Service For Linux
No fix yet
CRITICAL 9.8
CVE-2026-58586
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses…
No fix yet
CRITICAL 10.0
CVE-2026-57106
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
CRITICAL 10.0
CVE-2026-56163
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
HIGH 8.7
CVE-2026-55732
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …
No fix yet
MEDIUM 6.6
CVE-2026-55731
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4…
No fix yet
HIGH 8.7
CVE-2026-55730
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to exec…
No fix yet
HIGH 7.7
CVE-2026-55729
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthentica…
No fix yet
MEDIUM 6.5
CVE-2026-17059
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…
Build Of Keycloak
No fix yet