Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.6
CVE-2026-17688
Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17687
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17684
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had comprom…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17682
Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially p…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17681
Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17680
Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17676
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer p…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17675
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentiall…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17673
Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially pe…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17672
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17671
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendere…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17670
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17669
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sand…
Chrome
151.0.7922.72+
CRITICAL 9.1
CVE-2026-17666
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17652
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17656
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17655
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo…
Chrome
151.0.7922.72+
CRITICAL 9.6
CVE-2026-17651
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perfor…
Chrome
151.0.7922.72+
CRITICAL 9.8
CVE-2025-69943
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
Mitigation only
CRITICAL 9.8
CVE-2025-69942
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
No fix yet
CRITICAL 9.8
CVE-2025-67404
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla…
No fix yet
CRITICAL 9.8
CVE-2025-67403
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
No fix yet
CRITICAL 9.8
CVE-2025-65340
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
No fix yet
CRITICAL 10.0
CVE-2026-67429
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…
Patch available
CRITICAL 9.3
CVE-2026-67426
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…
Patch available
CRITICAL 10.0
CVE-2026-16326
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen…
No fix yet
CRITICAL 9.8
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-41939
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows u…
Mitigation only
CRITICAL 9.3
CVE-2026-18236
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in…
Patch available
CRITICAL 9.2
CVE-2026-8338
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malic…
No fix yet