Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.9
CVE-2026-54680
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer Fluen…
Patch available
CRITICAL 9.1
CVE-2026-51992
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …
Mitigation only
CRITICAL 9.1
CVE-2026-13697
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…
Undici
7.29.0 / 8.9.0+
CRITICAL 9.8
CVE-2026-67191
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write…
No fix yet
CRITICAL 9.8
CVE-2026-60113
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte…
Ait Dsn
2.2.2+
CRITICAL 9.8
CVE-2026-60112
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o…
Ait Gui
2.5.1+
CRITICAL 10.0
CVE-2026-54735
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in …
Prebid Server
4.4.0+
CRITICAL 9.8
CVE-2026-65888
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…
Gridbox
2.20.2+
CRITICAL 9.8
CVE-2026-65887
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…
Gridbox
2.20.2+
CRITICAL 9.4
CVE-2026-9177
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of the Axway SecureTransport product in vers…
No fix yet
CRITICAL 9.8
CVE-2026-65890
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…
Gridbox
2.20.2+
CRITICAL 9.8
CVE-2026-65884
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…
Gridbox
2.20.2+
CRITICAL 9.3
CVE-2026-0667
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of …
No fix yet
CRITICAL 9.8
CVE-2026-65883
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…
Aimy Captcha Less Form Guard
after 20.0
CRITICAL 9.8
CVE-2026-14900
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to…
No fix yet
CRITICAL 9.1
CVE-2026-14488
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission exten…
No fix yet
CRITICAL 9.8
CVE-2026-59243
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…
Apache Airflow Providers Fab
3.7.3+
CRITICAL 9.8
CVE-2026-58185
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-58179
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: fro…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-58177
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Se…
Traffic Server
10.1.4+
CRITICAL 9.1
CVE-2026-58163
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: …
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-58162
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server:…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2025-10656
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u…
No fix yet
CRITICAL 9.3
CVE-2026-58155
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Tr…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-58150
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic …
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-57834
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.3
CVE-2026-41920
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.1
CVE-2026-33267
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-18191
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden fu…
Mitigation only
CRITICAL 9.9
CVE-2026-63234
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessmen…
No fix yet