Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-54823
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
Mitigation only
HIGH 8.5
CVE-2026-54822
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
Mitigation only
HIGH 7.4
CVE-2026-54821
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
Mitigation only
MEDIUM 5.9
CVE-2026-52690
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that …
Mitigation only
MEDIUM 5.3
CVE-2026-42390
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.
Mitigation only
MEDIUM 5.3
CVE-2026-42389
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.
No fix yet
MEDIUM 5.9
CVE-2026-42388
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
Mitigation only
MEDIUM 5.9
CVE-2026-42387
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input …
Mitigation only
MEDIUM 5.3
CVE-2026-40012
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
Mitigation only
HIGH 8.4
CVE-2026-2815
Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
Mitigation only
HIGH 7.5
CVE-2026-27366
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
Mitigation only
MEDIUM 5.3
CVE-2026-40211
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will …
Mitigation only
MEDIUM 5.3
CVE-2026-40209
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by s…
Mitigation only
HIGH 7.5
CVE-2026-33612
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
Mitigation only
HIGH 8.2
CVE-2026-56091
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass.
Th…
Mitigation only
MEDIUM 6.4
CVE-2026-54226
A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0.
Users are recommended to upgrade to version 2.16.0…
No fix yet
CRITICAL 10.0
CVE-2026-46752
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0.
Users are r…
Mitigation only
MEDIUM 5.5
CVE-2026-46751
A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.
Users are recommended to upgrade to version 2.16.0…
No fix yet
CRITICAL 9.4
CVE-2026-41566
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: 2.8.0.
Users are re…
Mitigation only
MEDIUM 5.5
CVE-2026-56129
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A log…
Mitigation only
HIGH 7.5
CVE-2026-12937
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via …
Mitigation only
HIGH 7.5
CVE-2026-9702
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce ord…
Mitigation only
HIGH 8.8
CVE-2026-5305
The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replace…
Mitigation only
MEDIUM 6.5
CVE-2026-10824
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthentic…
Mitigation only
HIGH 7.5
CVE-2026-12053
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to…
GitLab
Mitigation only
MEDIUM 6.5
CVE-2026-2508
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and incl…
Mitigation only
MEDIUM 6.5
CVE-2026-12079
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 …
Mitigation only
HIGH 7.5
CVE-2026-12077
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to,…
Mitigation only
MEDIUM 6.4
CVE-2026-10833
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t…
Mitigation only
HIGH 8.8
CVE-2026-9155
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…
Sed
Mitigation only