Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-45870
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated …
No fix yet
MEDIUM 6.0
CVE-2026-10587
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.
No fix yet
MEDIUM 5.4
CVE-2026-63082
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers…
No fix yet
MEDIUM 5.4
CVE-2026-63081
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated att…
No fix yet
HIGH 8.6
CVE-2026-57206
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…
No fix yet
MEDIUM 6.8
CVE-2026-12379
An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not prop…
No fix yet
HIGH 8.8
CVE-2025-45868
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to ma…
No fix yet
HIGH 7.5
CVE-2026-59862
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descrip…
No fix yet
HIGH 8.3
CVE-2026-14254
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentic…
No fix yet
HIGH 8.8
CVE-2026-5674
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploi…
Mitigation only
MEDIUM 5.5
CVE-2026-9494
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT …
No fix yet
HIGH 8.6
CVE-2026-63306
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrar…
No fix yet
HIGH 8.1
CVE-2026-63305
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are conca…
No fix yet
HIGH 8.1
CVE-2026-63304
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function in…
Mitigation only
MEDIUM 5.0
CVE-2026-12391
An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma…
No fix yet
CRITICAL 9.0
CVE-2026-11386
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so…
No fix yet
CRITICAL 9.8
CVE-2023-49900
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
No fix yet
CRITICAL 9.8
CVE-2023-49899
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channe…
Mitigation only
CRITICAL 9.6
CVE-2026-22752
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.
This issue affects Spring Authorization Serv…
No fix yet
HIGH 7.2
CVE-2026-7543
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 d…
No fix yet
MEDIUM 6.7
CVE-2026-6424
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
No fix yet
HIGH 8.5
CVE-2026-6423
A local privilege escalation vulnerability in ESET Inspect Connector.
The vulnerability was caused by improper authentication in an IPC channel.
Mitigation only
HIGH 8.7
CVE-2026-58078
Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vu…
No fix yet
MEDIUM 5.3
CVE-2026-15106
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t…
No fix yet
HIGH 8.8
CVE-2026-15103
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr…
No fix yet
MEDIUM 6.4
CVE-2026-15099
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and includ…
No fix yet
MEDIUM 6.5
CVE-2026-15022
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all …
No fix yet
MEDIUM 6.4
CVE-2026-15021
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including,…
No fix yet
HIGH 8.1
CVE-2026-15008
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio…
No fix yet
HIGH 8.8
CVE-2026-15005
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missi…
Mitigation only