Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-65507
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
No fix yet
CRITICAL 9.8
CVE-2026-54489
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. …
Virtual Storage Integrator
10.11.1.0+
CRITICAL 9.1
CVE-2026-53976
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau…
Patch available
CRITICAL 9.8
CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b…
Patch available
CRITICAL 9.1
CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…
Apr Util
after 1.6.3
CRITICAL 9.1
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…
Apr Util
1.6.4+
CRITICAL 9.8
CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
No fix yet
CRITICAL 9.1
CVE-2026-64993
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c…
Rvtools
4.8.1+
CRITICAL 9.8
CVE-2026-5134
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…
No fix yet
CRITICAL 9.6
CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …
Glassfish
8.0.4+
CRITICAL 9.8
CVE-2026-68079
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-65583
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-63687
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-61466
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-66909
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-64597
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_close() replay
A response-bearing attempt …
No fix yet
CRITICAL 10.0
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…
Api Control Plane
4.1.0.257 / 4.2.0.197+
CRITICAL 9.8
CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitati…
Api Control Plane
4.0.0.384 / 4.1.0.248+
CRITICAL 9.4
CVE-2025-15039
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a…
Api Control Plane
1.4.0.137 / 1.4.0.143+
CRITICAL 9.1
CVE-2026-16054
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid no…
No fix yet
CRITICAL 9.1
CVE-2026-12713
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin…
No fix yet
CRITICAL 9.8
CVE-2026-67873
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encod…
No fix yet
CRITICAL 9.8
CVE-2026-67870
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remo…
No fix yet
CRITICAL 9.8
CVE-2026-52466
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ…
No fix yet
CRITICAL 9.3
CVE-2026-67531
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host …
Patch available
CRITICAL 9.6
CVE-2026-71319
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…
Patch available
CRITICAL 9.8
CVE-2025-63823
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic…
No fix yet
CRITICAL 9.9
CVE-2026-70615
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission …
No fix yet
CRITICAL 9.1
CVE-2026-17556
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…
Enterprise Server
3.17.19 / 3.18.13+