Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-75840
ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped re…
No fix yet
MEDIUM 5.1
CVE-2026-75838
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache…
No fix yet
CRITICAL 9.1
CVE-2026-75837
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi…
No fix yet
HIGH 8.8
CVE-2026-75836
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M…
No fix yet
MEDIUM 5.4
CVE-2026-75834
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). …
No fix yet
HIGH 7.1
CVE-2026-75830
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batc…
No fix yet
HIGH 8.1
CVE-2026-75829
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission …
No fix yet
HIGH 8.7
CVE-2026-75828
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value…
No fix yet
HIGH 8.8
CVE-2026-75827
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny…
No fix yet
MEDIUM 5.4
CVE-2026-75107
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la…
No fix yet
MEDIUM 5.9
CVE-2026-74907
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di…
No fix yet
HIGH 7.5
CVE-2026-74906
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…
No fix yet
HIGH 7.1
CVE-2026-74905
SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD…
No fix yet
HIGH 7.5
CVE-2026-74904
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…
No fix yet
HIGH 8.6
CVE-2026-74902
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting…
No fix yet
MEDIUM 5.7
CVE-2026-5224
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve…
No fix yet
HIGH 7.5
CVE-2026-15585
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra…
No fix yet
CRITICAL 9.3
CVE-2026-75626
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …
No fix yet
MEDIUM 5.3
CVE-2026-19608
A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T…
No fix yet
MEDIUM 5.4
CVE-2026-19447
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO…
No fix yet
CRITICAL 9.8
CVE-2026-34884
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking M…
No fix yet
HIGH 8.1
CVE-2026-15371
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked …
No fix yet
HIGH 7.2
CVE-2026-75091
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version…
No fix yet
CRITICAL 9.8
CVE-2026-15748
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…
No fix yet
HIGH 7.5
CVE-2026-11801
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…
No fix yet
CRITICAL 9.1
CVE-2026-75094
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid…
No fix yet
HIGH 7.3
CVE-2026-75089
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c…
No fix yet
MEDIUM 6.3
CVE-2026-75088
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi…
No fix yet
MEDIUM 6.3
CVE-2026-75087
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin…
No fix yet
MEDIUM 6.3
CVE-2026-75086
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.…
No fix yet