Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.4
CVE-2026-44326
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound …
Free5gc
4.2.2+
CRITICAL 9.4
CVE-2026-44315
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAu…
Free5gc
4.2.2+
CRITICAL 9.4
CVE-2026-49103
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detacha…
Patch available
CRITICAL 9.6
CVE-2026-45570
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remot…
Go Git
5.19.1+
CRITICAL 9.8
CVE-2026-8175
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…
Aspera High Speed Transfer Endpoint
after 4.4.6
CRITICAL 9.1
CVE-2026-7876
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …
Aspera High Speed Transfer Server For Cloud Pak For Integration
1.5.20+
CRITICAL 9.8
CVE-2026-7524
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
Langflow
after 1.9.1
CRITICAL 9.1
CVE-2026-46043
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
rxe_rcv() curr…
Linux Kernel
5.10.258 / 5.15.209+
CRITICAL 9.8
CVE-2026-46039
In the Linux kernel, the following vulnerability has been resolved:
rxgk: Fix potential integer overflow in length check
Fix potential integer over…
Linux Kernel
6.17 / 6.18.27+
CRITICAL 9.8
CVE-2026-45988
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix re-decryption of RESPONSE packets
If a RESPONSE packet gets a tempor…
Linux Kernel
6.6.140 / 6.12.86+
CRITICAL 9.8
CVE-2026-45972
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential UAF and double free in smb2_open_file()
Zero out @er…
Linux Kernel
6.1.165 / 6.6.128+
CRITICAL 9.8
CVE-2026-45898
In the Linux kernel, the following vulnerability has been resolved:
RDMA/iwcm: Fix workqueue list corruption by removing work_list
The commit e1168…
Linux Kernel
6.12.75 / 6.18.14+
CRITICAL 9.3
CVE-2026-35090
In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telepho…
Mitigation only
CRITICAL 9.3
CVE-2026-35087
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executi…
Mitigation only
CRITICAL 9.8
CVE-2024-40684
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…
Operations Analytics Log Analysis
Mitigation only
CRITICAL 9.3
CVE-2026-42761
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…
Mitigation only
CRITICAL 9.8
CVE-2026-42758
Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affe…
Mitigation only
CRITICAL 9.9
CVE-2026-42757
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-igni…
Mitigation only
CRITICAL 9.9
CVE-2026-42756
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Imag…
Mitigation only
CRITICAL 9.3
CVE-2026-42755
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allow…
Mitigation only
CRITICAL 9.9
CVE-2026-42748
Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue…
Mitigation only
CRITICAL 9.3
CVE-2026-42747
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-buil…
Mitigation only
CRITICAL 9.3
CVE-2026-42740
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Inj…
Mitigation only
CRITICAL 9.8
CVE-2026-42731
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This i…
Mitigation only
CRITICAL 9.3
CVE-2026-42727
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…
Mitigation only
CRITICAL 10.0
CVE-2026-8054
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and…
Patch available
CRITICAL 9.1
CVE-2026-49002
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system dat…
No fix yet
CRITICAL 9.8
CVE-2025-13392
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…
Diskstation Manager
7.2.2-72806-5+
CRITICAL 9.8
CVE-2025-12686
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allo…
Beestation Os
1.3.2+
CRITICAL 9.8
CVE-2026-8760
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplet…
Mitigation only