Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-16051
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no…
No fix yet
CRITICAL 9.8
CVE-2026-15039
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t…
No fix yet
CRITICAL 9.9
CVE-2026-72526
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from…
No fix yet
CRITICAL 9.6
CVE-2026-70398
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated u…
No fix yet
CRITICAL 9.1
CVE-2026-68431
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate minimum PDU size for transform requests
The receive path applie…
No fix yet
CRITICAL 9.8
CVE-2026-68067
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the accoun…
No fix yet
CRITICAL 9.1
CVE-2026-67568
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which …
No fix yet
CRITICAL 9.6
CVE-2026-5917
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all…
No fix yet
CRITICAL 9.1
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…
Httpclient
5.6.4+
CRITICAL 9.4
CVE-2026-66147
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…
No fix yet
CRITICAL 9.9
CVE-2026-48765
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from…
Patch available
CRITICAL 9.8
CVE-2026-73034
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s…
Patch available
CRITICAL 9.6
CVE-2026-73032
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou…
Patch available
CRITICAL 9.1
CVE-2026-66145
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…
No fix yet
CRITICAL 10.0
CVE-2026-45618
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…
No fix yet
CRITICAL 9.8
CVE-2026-16230
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun…
No fix yet
CRITICAL 9.8
CVE-2026-73211
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…
Patch available
CRITICAL 9.3
CVE-2026-73090
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…
Patch available
CRITICAL 10.0
CVE-2026-71398
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
CRITICAL 9.1
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…
No fix yet
CRITICAL 9.8
CVE-2026-69102
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica…
Patch available
CRITICAL 9.0
CVE-2026-48381
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…
No fix yet
CRITICAL 9.6
CVE-2026-47705
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sani…
Patch available
CRITICAL 10.0
CVE-2026-27302
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
CRITICAL 9.6
CVE-2026-71384
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…
Coldfusion
No fix yet
CRITICAL 9.3
CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
1.19.1+
CRITICAL 9.8
CVE-2026-65791
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.8
CVE-2026-65768
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…
Teams
1.0.0.2026133602+
CRITICAL 9.8
CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+