Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-50627
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-49875
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.4
CVE-2026-11535
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’…
No fix yet
CRITICAL 9.8
CVE-2026-48611
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthoriz…
Mitigation only
CRITICAL 9.9
CVE-2026-47370
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…
Mitigation only
CRITICAL 9.9
CVE-2026-47369
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…
Mitigation only
CRITICAL 9.9
CVE-2026-47367
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agen…
Mitigation only
CRITICAL 9.9
CVE-2026-47365
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant…
Mitigation only
CRITICAL 9.8
CVE-2026-45060
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind…
Mitigation only
CRITICAL 9.8
CVE-2026-42846
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user…
Mitigation only
CRITICAL 9.8
CVE-2026-49060
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation.
This issue affects Hippoo Mobile App …
Mitigation only
CRITICAL 9.3
CVE-2026-42647
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.
…
Mitigation only
CRITICAL 9.3
CVE-2026-39494
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind …
Mitigation only
CRITICAL 9.6
CVE-2026-12027
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process …
Chrome
149.0.7827.115+
CRITICAL 9.0
CVE-2026-41005
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity P…
Mitigation only
CRITICAL 9.4
CVE-2026-49973
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial…
Patch available
CRITICAL 9.5
CVE-2026-47174
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull…
Mitigation only
CRITICAL 9.5
CVE-2026-47172
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged de…
Mitigation only
CRITICAL 9.1
CVE-2026-45177
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauth…
Idira Secrets Manager Edge
1.8+
CRITICAL 9.8
CVE-2026-49261
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8…
MariaDB
10.6.27 / 10.11.18+
CRITICAL 9.1
CVE-2026-9648
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alterna…
Patch available
CRITICAL 9.9
CVE-2026-11839
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web S…
Mitigation only
CRITICAL 9.8
CVE-2026-38581
SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor…
Mitigation only
CRITICAL 9.8
CVE-2026-7852
Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion.
This issue affects Lim…
Mitigation only
CRITICAL 9.8
CVE-2026-11561
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Inform…
Mitigation only
CRITICAL 9.4
CVE-2026-4764
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit…
Mitigation only
CRITICAL 9.8
CVE-2026-41699
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious…
Spring For Graphql
1.3.9 / 1.4.5.1+
CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…
Peoplesoft Enterprise Peopletools
Mitigation only
CRITICAL 9.6
CVE-2026-46703
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …
Mitigation only
CRITICAL 10.0
CVE-2026-46695
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …
Patch available