Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2026-1771
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version…
No fix yet
HIGH 7.3
CVE-2026-15370
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack…
Hardened Images
No fix yet
MEDIUM 5.3
CVE-2026-8593
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users …
No fix yet
HIGH 7.1
CVE-2026-3183
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
No fix yet
HIGH 7.5
CVE-2026-8082
The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce or…
No fix yet
MEDIUM 5.4
CVE-2026-14184
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, al…
No fix yet
MEDIUM 6.5
CVE-2026-13694
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing…
No fix yet
MEDIUM 5.9
CVE-2026-13693
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a no…
No fix yet
HIGH 8.8
CVE-2026-11767
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti…
Mitigation only
MEDIUM 6.8
CVE-2026-15927
A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
exte…
No fix yet
MEDIUM 5.8
CVE-2026-15811
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe s…
No fix yet
CRITICAL 9.8
CVE-2026-13439
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, a…
No fix yet
MEDIUM 6.4
CVE-2026-15156
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read…
No fix yet
MEDIUM 6.8
CVE-2026-59776
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, in…
No fix yet
HIGH 7.2
CVE-2026-6952
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5…
No fix yet
MEDIUM 6.3
CVE-2026-16334
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder…
No fix yet
HIGH 7.3
CVE-2026-16332
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul…
No fix yet
HIGH 7.3
CVE-2026-16331
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…
No fix yet
HIGH 7.3
CVE-2026-16330
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T…
No fix yet
HIGH 7.3
CVE-2026-16329
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation…
No fix yet
HIGH 7.3
CVE-2026-16327
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …
No fix yet
CRITICAL 9.8
CVE-2026-64625
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command…
No fix yet
MEDIUM 5.6
CVE-2026-57852
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured …
No fix yet
HIGH 8.2
CVE-2026-57495
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to v…
Mitigation only
HIGH 7.1
CVE-2026-57494
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated Agent…
No fix yet
HIGH 7.1
CVE-2026-55550
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…
No fix yet
HIGH 7.6
CVE-2026-55544
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…
No fix yet
CRITICAL 9.8
CVE-2026-52656
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary …
No fix yet
HIGH 7.5
CVE-2026-51031
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker …
No fix yet
MEDIUM 6.1
CVE-2026-51025
Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageCo…
No fix yet