Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-9205
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
Langflow
1.11.0+
CRITICAL 9.1
CVE-2026-8470
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random mod…
Langflow
1.11.0+
CRITICAL 10.0
CVE-2026-48168
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection b…
Patch available
CRITICAL 9.0
CVE-2026-70426
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2…
No fix yet
CRITICAL 9.1
CVE-2026-20310
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…
No fix yet
CRITICAL 9.9
CVE-2026-20304
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…
No fix yet
CRITICAL 9.9
CVE-2026-20303
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…
No fix yet
CRITICAL 9.8
CVE-2026-20272
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…
Ios Xe
No fix yet
CRITICAL 9.0
CVE-2026-20267
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…
Ios Xe
No fix yet
CRITICAL 9.8
CVE-2026-17617
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…
Application Gateway Operator
after 26.6.0
CRITICAL 9.3
CVE-2026-9195
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an…
Mitigation only
CRITICAL 9.9
CVE-2026-9193
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate…
No fix yet
CRITICAL 9.8
CVE-2026-9192
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote …
No fix yet
CRITICAL 9.1
CVE-2026-9190
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypa…
No fix yet
CRITICAL 9.9
CVE-2026-8709
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …
Mitigation only
CRITICAL 9.8
CVE-2026-8400
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…
Websphere Application Server
No fix yet
CRITICAL 9.1
CVE-2026-7557
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12…
No fix yet
CRITICAL 9.9
CVE-2026-7329
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.…
No fix yet
CRITICAL 9.1
CVE-2026-60053
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Administrative API keys remained u…
Answer
2.0.2+
CRITICAL 9.8
CVE-2026-16442
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.4
CVE-2026-15587
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to…
Mitigation only
CRITICAL 9.8
CVE-2026-10025
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…
Qradar Security Information And Event Manager
No fix yet
CRITICAL 9.1
CVE-2026-16443
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.8
CVE-2026-71289
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service'…
No fix yet
CRITICAL 9.8
CVE-2026-71278
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th…
Mitigation only
CRITICAL 9.1
CVE-2026-71277
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never …
No fix yet
CRITICAL 9.9
CVE-2026-71268
OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t…
No fix yet
CRITICAL 9.8
CVE-2026-71267
microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a…
No fix yet
CRITICAL 9.1
CVE-2026-71263
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater…
No fix yet
CRITICAL 9.8
CVE-2026-71262
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersC…
Mitigation only