Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.0
CVE-2026-68820 KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.6
CVE-2026-20349 KEV
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T…
Adaptive Security Appliance Software
No fix yet
CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …
Metabase
0.58.24 / 0.59.21+
CRITICAL 9.8
CVE-2026-65400 KEV
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…
macOS
14.8.9 / 15.7.9+
HIGH 8.1
CVE-2026-18577 KEV
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
N Central
2026.3+
HIGH 7.4
CVE-2026-18556 KEV
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-centra…
N Central
after 2026.1
CRITICAL 9.8
CVE-2026-59310 KEV
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…
Vcenter Server
No fix yet
MEDIUM 5.3
CVE-2026-20316 KEV
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…
Secure Firewall Management Center
after 10.0.1
CRITICAL 9.8
CVE-2026-63077 KEVEPSS 11%
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
2025.11.7 / 2026.1.3+
CRITICAL 10.0
CVE-2026-16812 KEV
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…
Velocloud Orchestrator
5.2.3.14 / 6.1.3.4+
CRITICAL 9.8
CVE-2026-16232 KEVEPSS 73%
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…
Multi Domain Security Management
No fix yet
CRITICAL 9.8
CVE-2026-63030 KEVEPSS 96%
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…
WordPress
6.9.5 / 7.0.2+
MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…
WordPress
6.8.6 / 6.9.5+
CRITICAL 9.8
CVE-2026-9198 KEVEPSS 17%
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…
Langflow
1.10.1+
HIGH 8.1
CVE-2021-27137 KEVEPSS 16%
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…
Dd Wrt
45724+
HIGH 7.2
CVE-2026-15410 KEVEPSS 76%
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…
Sma6210 Firmware
Mitigation only
CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…
Sma6210 Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-55040 KEV
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 7.8
CVE-2026-56155 KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-56291 KEVEPSS 76%
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to…
Forms
2.4.1+
CRITICAL 10.0
CVE-2026-48282 KEVEPSS 99%
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2026-56290 KEVEPSS 83%
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…
Page Builder Ck
3.6.0+
HIGH 8.4
CVE-2026-55255 KEVEPSS 29%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…
Langflow
1.9.1+
CRITICAL 9.8
CVE-2026-48939 KEVEPSS 83%
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP…
Icagenda
3.9.15 / 4.0.8+
CRITICAL 9.8
CVE-2026-48908 KEVEPSS 88%
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio…
Sp Page Builder
6.6.2+
CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…
Flexplm
11.0m030+
MEDIUM 6.5
CVE-2026-20262 KEVEPSS 28%
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fi…
Catalyst Sd Wan Manager
20.9.9.2 / 20.12.7.2+