Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-18249
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from…
I
No fix yet
CRITICAL 10.0
CVE-2026-18193
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
I
No fix yet
CRITICAL 9.8
CVE-2026-17482
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
Documentation Offline
1.5.1+
CRITICAL 9.8
CVE-2026-17481
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.
Documentation Offline
1.5.1+
CRITICAL 9.6
CVE-2026-17101
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
I
No fix yet
CRITICAL 9.9
CVE-2026-73656
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…
Patch available
CRITICAL 9.8
CVE-2026-19747
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu…
No fix yet
CRITICAL 9.8
CVE-2026-17206
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
I
after 7.6
CRITICAL 9.8
CVE-2026-16961
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …
I
No fix yet
CRITICAL 9.8
CVE-2026-16867
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…
I
No fix yet
CRITICAL 9.1
CVE-2026-16815
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…
I
No fix yet
CRITICAL 9.4
CVE-2026-14525
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…
Websphere Application Server
26.0.0.9+
CRITICAL 9.4
CVE-2026-73653
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…
Patch available
CRITICAL 9.8
CVE-2026-17197
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
I
No fix yet
CRITICAL 9.8
CVE-2026-73649
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr…
Patch available
CRITICAL 9.6
CVE-2026-73644
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org…
Patch available
CRITICAL 9.1
CVE-2026-73567
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.…
Patch available
CRITICAL 9.8
CVE-2026-67614
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…
No fix yet
CRITICAL 9.1
CVE-2026-58508
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
No fix yet
CRITICAL 9.1
CVE-2026-58443
Public-only repository tokens can update private PR head branches
No fix yet
CRITICAL 9.1
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
No fix yet
CRITICAL 9.1
CVE-2026-56750
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
No fix yet
CRITICAL 9.8
CVE-2026-56654
Privilege Escalation via Access Token Scope Escalation in API
No fix yet
CRITICAL 9.6
CVE-2026-56443
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
No fix yet
CRITICAL 9.1
CVE-2026-55982
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
No fix yet
CRITICAL 9.1
CVE-2026-13051
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an …
Patch available
CRITICAL 9.1
CVE-2022-4993
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_er…
Patch available
CRITICAL 9.8
CVE-2026-73533
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned upda…
No fix yet
CRITICAL 9.8
CVE-2026-73532
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat…
No fix yet
CRITICAL 9.1
CVE-2026-53791
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access contro…
No fix yet