Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2026-66649
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66609
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
No fix yet
CRITICAL 9.1
CVE-2026-66600
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66593
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66592
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66583
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
No fix yet
CRITICAL 9.8
CVE-2025-15689
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
No fix yet
CRITICAL 9.3
CVE-2025-15688
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
No fix yet
CRITICAL 9.1
CVE-2026-13097
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se…
No fix yet
CRITICAL 9.6
CVE-2026-11861
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti…
No fix yet
CRITICAL 9.8
CVE-2026-14950
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…
No fix yet
CRITICAL 9.8
CVE-2026-75860
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r…
No fix yet
CRITICAL 9.8
CVE-2026-76850
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py r…
Patch available
CRITICAL 9.9
CVE-2026-76590
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cg…
No fix yet
CRITICAL 9.9
CVE-2026-76589
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the …
No fix yet
CRITICAL 9.1
CVE-2026-76404
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating …
No fix yet
CRITICAL 9.4
CVE-2026-76312
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) sou…
Splunk
9.4.14 / 10.0.9+
CRITICAL 9.4
CVE-2026-76311
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…
Splunk
9.4.14 / 10.0.9+
CRITICAL 9.4
CVE-2026-76310
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…
Splunk
9.4.14 / 10.0.9+
CRITICAL 9.9
CVE-2026-76584
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin…
No fix yet
CRITICAL 9.1
CVE-2026-75595
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHand…
Patch available
CRITICAL 9.6
CVE-2026-53548
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:…
Patch available
CRITICAL 9.6
CVE-2026-53546
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket …
Patch available
CRITICAL 9.8
CVE-2026-53545
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/…
Patch available
CRITICAL 9.8
CVE-2026-63722
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands b…
No fix yet
CRITICAL 9.9
CVE-2026-55089
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in th…
Patch available
CRITICAL 9.6
CVE-2026-55085
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a num…
Patch available
CRITICAL 10.0
CVE-2026-22306
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive informat…
No fix yet
CRITICAL 9.8
CVE-2026-16919
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied …
Aix
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16917
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
Vios
4.1.0.50 / 4.1.1.30+