Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-66620
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
No fix yet
HIGH 8.8
CVE-2026-61407
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attack…
No fix yet
CRITICAL 9.8
CVE-2026-59940
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…
No fix yet
MEDIUM 5.9
CVE-2026-50139
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the…
No fix yet
HIGH 8.1
CVE-2026-50138
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-…
No fix yet
HIGH 7.2
CVE-2026-32553
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
No fix yet
HIGH 7.5
CVE-2026-32549
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
No fix yet
HIGH 7.1
CVE-2026-32547
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
No fix yet
HIGH 7.5
CVE-2026-32481
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
No fix yet
CRITICAL 9.9
CVE-2026-32474
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
No fix yet
HIGH 7.2
CVE-2026-32473
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
No fix yet
HIGH 7.5
CVE-2026-32472
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-32470
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
No fix yet
HIGH 7.4
CVE-2026-18534
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to i…
No fix yet
HIGH 7.5
CVE-2026-32468
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
No fix yet
MEDIUM 6.0
CVE-2026-32467
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
No fix yet
HIGH 8.5
CVE-2026-32466
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
No fix yet
HIGH 8.8
CVE-2026-32465
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
No fix yet
HIGH 8.1
CVE-2026-32464
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
No fix yet
CRITICAL 9.9
CVE-2026-32463
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
No fix yet
CRITICAL 9.9
CVE-2026-32444
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
No fix yet
HIGH 7.1
CVE-2026-32333
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
No fix yet
HIGH 7.5
CVE-2026-28571
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
No fix yet
HIGH 8.1
CVE-2026-28570
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28569
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
No fix yet
HIGH 7.1
CVE-2026-28568
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
No fix yet
HIGH 7.5
CVE-2026-28567
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
No fix yet
CRITICAL 9.6
CVE-2026-28192
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
No fix yet
HIGH 8.8
CVE-2026-28191
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
No fix yet
HIGH 8.8
CVE-2026-24301
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …
No fix yet