Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2026-14330
Multiple unbounded alloca() calls in the PulseAudio protocol server.
Mitigation only
MEDIUM 6.5
CVE-2026-14324
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Mitigation only
HIGH 7.7
CVE-2026-13602
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:
…
Mitigation only
MEDIUM 6.4
CVE-2026-12374
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before…
Mitigation only
CRITICAL 9.8
CVE-2026-57692
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.
This issue affects PrivateContent: from n/a throug…
Mitigation only
CRITICAL 9.0
CVE-2026-13603
The payment integration pretix-oppwa provides support
for the payment providers VR Payment, Hobex, and potentially others
based on Oppwa's technolo…
Mitigation only
HIGH 8.1
CVE-2026-5120
A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from a…
Mitigation only
MEDIUM 6.5
CVE-2026-53909
MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse…
Mycomplianceoffice
Mitigation only
MEDIUM 5.4
CVE-2026-53907
MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl…
Mycomplianceoffice
Mitigation only
MEDIUM 6.5
CVE-2026-53902
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u…
Mycomplianceoffice
Mitigation only
HIGH 8.2
CVE-2026-53906
MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the …
Mycomplianceoffice
Mitigation only
HIGH 7.1
CVE-2026-53905
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe…
Mycomplianceoffice
Mitigation only
HIGH 7.1
CVE-2026-53904
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidate…
Mco
Mitigation only
HIGH 8.1
CVE-2026-53903
MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement …
Mycomplianceoffice
Mitigation only
HIGH 8.8
CVE-2026-13228
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ve…
Mitigation only
HIGH 7.2
CVE-2026-12142
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter i…
Mitigation only
MEDIUM 6.4
CVE-2026-10095
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and incl…
Mitigation only
MEDIUM 5.3
CVE-2026-27435
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects…
Mitigation only
MEDIUM 6.5
CVE-2026-13454
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ…
Mitigation only
MEDIUM 6.1
CVE-2026-12754
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all…
Mitigation only
MEDIUM 5.9
CVE-2026-56016
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources.
The generate_id method builds the ses…
Mitigation only
HIGH 7.2
CVE-2026-50043
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnera…
Mitigation only
MEDIUM 6.4
CVE-2026-13733
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, a…
Mitigation only
MEDIUM 6.4
CVE-2026-12732
The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, …
Mitigation only
HIGH 8.7
CVE-2026-12577
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
No fix yet
HIGH 7.5
CVE-2026-12576
DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
No fix yet
HIGH 7.5
CVE-2026-12575
DVP80ES3 with
Improper Resource Shutdown or Release vulnerability.
No fix yet
HIGH 8.8
CVE-2026-12224
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, …
Mitigation only
HIGH 8.8
CVE-2026-12158
The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…
Mitigation only
CRITICAL 9.8
CVE-2026-11387
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation v…
Mitigation only