Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-74886
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules tha…
No fix yet
HIGH 7.5
CVE-2026-74884
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitiz…
No fix yet
HIGH 8.8
CVE-2026-74883
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access metho…
No fix yet
HIGH 7.5
CVE-2026-74882
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityPro…
No fix yet
MEDIUM 6.5
CVE-2026-74881
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create m…
No fix yet
CRITICAL 9.8
CVE-2026-74880
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract t…
No fix yet
HIGH 7.5
CVE-2026-74879
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception str…
No fix yet
CRITICAL 9.8
CVE-2026-74878
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on …
No fix yet
HIGH 8.8
CVE-2026-74877
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clien…
No fix yet
CRITICAL 9.8
CVE-2026-74876
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver…
No fix yet
CRITICAL 9.8
CVE-2026-74875
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata …
No fix yet
HIGH 7.5
CVE-2026-74874
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_se…
No fix yet
MEDIUM 5.5
CVE-2026-74873
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Att…
No fix yet
CRITICAL 9.8
CVE-2026-74872
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob pat…
No fix yet
MEDIUM 6.2
CVE-2026-74871
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key ge…
No fix yet
HIGH 7.7
CVE-2026-74869
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumer…
No fix yet
HIGH 7.5
CVE-2026-74868
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTranspo…
No fix yet
MEDIUM 6.3
CVE-2026-74842
A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the fi…
No fix yet
HIGH 8.2
CVE-2026-74802
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disa…
No fix yet
HIGH 8.2
CVE-2026-74801
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper …
No fix yet
CRITICAL 9.0
CVE-2026-74800
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si…
No fix yet
CRITICAL 9.3
CVE-2026-74799
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set…
No fix yet
HIGH 8.7
CVE-2026-74798
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on t…
No fix yet
HIGH 8.8
CVE-2026-74845
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers …
No fix yet
MEDIUM 5.5
CVE-2026-49308
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
No fix yet
MEDIUM 6.2
CVE-2026-49307
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentia…
No fix yet
MEDIUM 6.2
CVE-2026-49305
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.
No fix yet
MEDIUM 6.2
CVE-2026-49304
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.
No fix yet
MEDIUM 5.1
CVE-2026-49303
Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.
No fix yet
MEDIUM 6.2
CVE-2026-49302
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confide…
No fix yet