Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2026-16449
A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem…
No fix yet
HIGH 7.8
CVE-2026-8933
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct …
No fix yet
HIGH 7.5
CVE-2026-65052
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to in…
No fix yet
MEDIUM 6.5
CVE-2026-65051
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated atta…
No fix yet
MEDIUM 6.5
CVE-2026-65050
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submi…
No fix yet
CRITICAL 9.3
CVE-2026-65049
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administr…
Mitigation only
CRITICAL 9.3
CVE-2026-65048
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatab…
No fix yet
HIGH 7.5
CVE-2026-59850
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data …
Hardened Images
No fix yet
HIGH 7.5
CVE-2026-59849
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when …
Hardened Images
No fix yet
HIGH 8.8
CVE-2026-59851
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ…
Hardened Images
No fix yet
MEDIUM 5.3
CVE-2026-56584
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vu…
Intelliops Event Management
No fix yet
MEDIUM 6.3
CVE-2026-16448
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…
No fix yet
HIGH 8.4
CVE-2026-15226
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default s…
No fix yet
MEDIUM 5.6
CVE-2024-5300
An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The …
No fix yet
MEDIUM 6.3
CVE-2026-9499
An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that…
No fix yet
MEDIUM 5.3
CVE-2026-59848
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing …
Hardened Images
No fix yet
HIGH 7.5
CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al…
Hardened Images
No fix yet
HIGH 7.3
CVE-2026-16447
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The man…
No fix yet
CRITICAL 9.8
CVE-2025-66390
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an at…
No fix yet
MEDIUM 6.1
CVE-2026-8284
URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation.
This issue aff…
No fix yet
MEDIUM 6.5
CVE-2026-6792
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels.
Thi…
No fix yet
CRITICAL 9.8
CVE-2026-65008
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), w…
No fix yet
CRITICAL 9.6
CVE-2026-65007
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGen…
No fix yet
MEDIUM 5.4
CVE-2026-64628
Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads con…
No fix yet
MEDIUM 6.9
CVE-2026-64627
Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mo…
No fix yet
MEDIUM 5.9
CVE-2026-59845
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b…
Hardened Images
No fix yet
MEDIUM 5.3
CVE-2026-59842
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copie…
Hardened Images
No fix yet
MEDIUM 6.5
CVE-2026-59844
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser…
Hardened Images
No fix yet
MEDIUM 6.5
CVE-2026-59843
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write…
Hardened Images
No fix yet
CRITICAL 9.8
CVE-2026-1617
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspo…
No fix yet