Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-77647
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to inc…
No fix yet
CRITICAL 9.2
CVE-2026-77645
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…
No fix yet
CRITICAL 9.3
CVE-2026-77644
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
No fix yet
CRITICAL 9.8
CVE-2026-72843
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, wh…
No fix yet
CRITICAL 9.9
CVE-2026-69851
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 10.0
CVE-2026-69836
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
No fix yet
CRITICAL 10.0
CVE-2026-69555
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 9.6
CVE-2026-69400
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
No fix yet
CRITICAL 9.9
CVE-2026-68789
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…
No fix yet
CRITICAL 9.9
CVE-2026-68782
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…
No fix yet
CRITICAL 9.1
CVE-2026-66309
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 10.0
CVE-2026-65816
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 10.0
CVE-2026-65801
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 10.0
CVE-2026-65770
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthori…
No fix yet
CRITICAL 9.9
CVE-2026-63509
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 9.3
CVE-2026-62834
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
No fix yet
CRITICAL 9.4
CVE-2026-55769
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened …
Patch available
CRITICAL 9.9
CVE-2026-18835
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralizatio…
No fix yet
CRITICAL 9.3
CVE-2026-17422
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
No fix yet
CRITICAL 9.8
CVE-2026-17160
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computat…
No fix yet
CRITICAL 9.8
CVE-2026-17157
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
No fix yet
CRITICAL 9.8
CVE-2026-17152
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
No fix yet
CRITICAL 9.8
CVE-2026-17145
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
No fix yet
CRITICAL 9.8
CVE-2026-17142
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
No fix yet
CRITICAL 9.8
CVE-2026-17141
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
No fix yet
CRITICAL 9.8
CVE-2026-17136
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
No fix yet
CRITICAL 9.8
CVE-2026-17122
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
No fix yet
CRITICAL 9.8
CVE-2026-17118
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
No fix yet
CRITICAL 9.8
CVE-2026-17040
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
No fix yet
CRITICAL 9.1
CVE-2026-71485
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea…
Patch available