Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.3
CVE-2026-44672
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3…
Mitigation only
CRITICAL 9.3
CVE-2026-8980
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the pa…
Mitigation only
CRITICAL 9.3
CVE-2026-8979
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the …
Mitigation only
CRITICAL 9.9
CVE-2026-9813
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/ca…
Flowintel
3.3.0+
CRITICAL 9.8
CVE-2026-46195
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate dacloffset before building DACL pointers
parse_sec_desc()…
Linux Kernel
6.6.140 / 6.12.88+
CRITICAL 9.1
CVE-2026-46185
In the Linux kernel, the following vulnerability has been resolved:
smb/client: fix out-of-bounds read in symlink_data()
Since smb2_check_message()…
Linux Kernel
6.1.175 / 6.6.140+
CRITICAL 9.1
CVE-2026-46155
In the Linux kernel, the following vulnerability has been resolved:
smb/client: fix out-of-bounds read in smb2_compound_op()
If a server sends a tr…
Linux Kernel
6.6.140 / 6.12.88+
CRITICAL 9.8
CVE-2026-46137
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: fix potential data-race
This mptcp_pm_add_timer() help…
Linux Kernel
5.10.259 / 5.15.210+
CRITICAL 9.8
CVE-2026-46135
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fix race between ICReq handling and queue teardown
nvmet_tcp_handle_…
Linux Kernel
6.12.88 / 6.18.30+
CRITICAL 9.1
CVE-2026-46119
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix slab-out-of-bounds access in auth message processing
If a (potenti…
Linux Kernel
5.15.209 / 6.1.175+
CRITICAL 9.8
CVE-2026-46115
In the Linux kernel, the following vulnerability has been resolved:
block: add pgmap check to biovec_phys_mergeable
biovec_phys_mergeable() is used…
Linux Kernel
6.6.140 / 6.12.88+
CRITICAL 9.8
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …
Openshift Container Platform
4.21.0+
CRITICAL 9.0
CVE-2026-32999
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitr…
Mitigation only
CRITICAL 9.4
CVE-2026-32998
This vulnerability in Veeam Service Provider Console allows for remote code execution.
No fix yet
CRITICAL 9.4
CVE-2026-9739
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` …
Patch available
CRITICAL 9.8
CVE-2026-45083
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer…
Patch available
CRITICAL 9.8
CVE-2026-8364
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL …
Mitigation only
CRITICAL 9.8
CVE-2026-8363
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
Mitigation only
CRITICAL 9.8
CVE-2026-8362
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
Mitigation only
CRITICAL 9.9
CVE-2026-45102
OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive.…
Mitigation only
CRITICAL 9.8
CVE-2026-44888
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplie…
Mitigation only
CRITICAL 9.8
CVE-2026-44887
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitra…
Mitigation only
CRITICAL 9.3
CVE-2026-44590
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.…
Mitigation only
CRITICAL 9.0
CVE-2026-48150
Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes …
Mitigation only
CRITICAL 9.9
CVE-2026-46425
Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCI…
Mitigation only
CRITICAL 10.0
CVE-2026-45087EPSS 13%
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf…
Mitigation only
CRITICAL 9.8
CVE-2026-48027 KEV
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and remove…
Nx Console
Mitigation only
CRITICAL 10.0
CVE-2026-44330
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbo…
Free5gc
4.2.2+
CRITICAL 10.0
CVE-2026-44329
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b…
Free5gc
4.2.2+
CRITICAL 10.0
CVE-2026-44327
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2…
Free5gc
4.2.2+