Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-43694
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may…
macOS
14.8.8 / 15.7.8+
CRITICAL 9.8
CVE-2026-43682
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote u…
macOS
14.8.8 / 15.7.8+
CRITICAL 9.8
CVE-2026-39873
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting…
macOS
14.8.8 / 15.7.8+
CRITICAL 9.8
CVE-2026-28982
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote us…
macOS
14.8.8 / 15.7.8+
CRITICAL 9.8
CVE-2026-28928
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, w…
Ipados
26.6+
CRITICAL 9.8
CVE-2026-28911
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to c…
macOS
14.8.8 / 26.6+
CRITICAL 9.8
CVE-2026-66014
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker …
Artifactory
7.111.18 / 7.117.25+
CRITICAL 9.8
CVE-2026-55579
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default…
No fix yet
CRITICAL 9.9
CVE-2026-48030EPSS 5%
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability i…
No fix yet
CRITICAL 9.1
CVE-2026-45623
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.…
Postcss
8.5.12+
CRITICAL 9.1
CVE-2026-17552
Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call.
When the rewr…
Patch available
CRITICAL 9.8
CVE-2026-63077 KEVEPSS 12%
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
2025.11.7 / 2026.1.3+
CRITICAL 9.1
CVE-2026-17191
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend q…
No fix yet
CRITICAL 9.4
CVE-2026-66398
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGUR…
No fix yet
CRITICAL 9.6
CVE-2026-66395
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to exe…
No fix yet
CRITICAL 9.1
CVE-2026-51300
A use-after-free vulnerability exists in the expression parsing and memory management logic of SQLite 3.41. After invoking sqlite3ExprDelete to relea…
Mitigation only
CRITICAL 9.8
CVE-2026-51303
A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprLi…
No fix yet
CRITICAL 10.0
CVE-2026-16812 KEV
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…
Velocloud Orchestrator
5.2.3.14 / 6.1.3.4+
CRITICAL 9.1
CVE-2025-50455
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vuln…
No fix yet
CRITICAL 9.3
CVE-2026-59550
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
No fix yet
CRITICAL 9.3
CVE-2026-59549
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
No fix yet
CRITICAL 9.3
CVE-2026-59538
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
No fix yet
CRITICAL 9.3
CVE-2026-59533
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-59527
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65879
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret a…
No fix yet
CRITICAL 9.2
CVE-2026-65876
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMo…
No fix yet
CRITICAL 9.2
CVE-2026-65766
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynami…
No fix yet
CRITICAL 9.8
CVE-2026-61511
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the …
No fix yet
CRITICAL 9.1
CVE-2026-58662
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift…
Thrift
0.24.0+
CRITICAL 9.1
CVE-2026-58023
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrad…
Thrift
0.24.0+