Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-64303
In the Linux kernel, the following vulnerability has been resolved:
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
When dmaeng…
No fix yet
CRITICAL 9.1
CVE-2026-64269
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
When the …
Linux Kernel
5.15.212 / 6.1.178+
CRITICAL 9.8
CVE-2026-64268
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: bound Read Response placement to the RREAD length
In drivers/infiniba…
Linux Kernel
5.10.261 / 5.15.212+
CRITICAL 9.1
CVE-2026-64257
In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject overlapping data areas in SMB2 responses
Commit 53b7c271f06…
Linux Kernel
5.11 / 5.16+
CRITICAL 9.8
CVE-2026-16766
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
Options are passed directly t…
No fix yet
CRITICAL 9.8
CVE-2026-16280
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 …
Ddk
26.1+
CRITICAL 9.8
CVE-2026-61884
The web management interface of Tycon Systems TPDIN-Monitor-WEB2
does not perform server-side validation of credentials during the login process. B…
No fix yet
CRITICAL 9.1
CVE-2026-48021
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…
No fix yet
CRITICAL 9.8
CVE-2026-64232
In the Linux kernel, the following vulnerability has been resolved:
block: recompute nr_integrity_segments in blk_insert_cloned_request
blk_insert_…
Linux Kernel
6.12.92 / 6.18.34+
CRITICAL 9.8
CVE-2026-64216
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
netfs_unlock_ab…
Linux Kernel
6.18.34 / 7.0.11+
CRITICAL 9.8
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Azure App Service For Linux
No fix yet
CRITICAL 9.8
CVE-2026-58586
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses…
No fix yet
CRITICAL 10.0
CVE-2026-57106
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
CRITICAL 10.0
CVE-2026-56163
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
CRITICAL 9.2
CVE-2026-12503
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A6…
No fix yet
CRITICAL 9.8
CVE-2026-16634
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.
The tomlc99 library is no longer maintained, and has…
Mitigation only
CRITICAL 9.3
CVE-2026-24727
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System …
No fix yet
CRITICAL 9.8
CVE-2026-15704
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon…
Patch available
CRITICAL 9.1
CVE-2026-12877
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it…
No fix yet
CRITICAL 9.8
CVE-2026-62825
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Azure Key Vault
No fix yet
CRITICAL 9.8
CVE-2026-58275
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Azure Dns
No fix yet
CRITICAL 10.0
CVE-2026-56191
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Exchange Online
No fix yet
CRITICAL 9.8
CVE-2026-56165
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Account
No fix yet
CRITICAL 9.9
CVE-2026-56160
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Azure Red Hat Openshift
No fix yet
CRITICAL 9.9
CVE-2026-50517
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
365 Copilot
No fix yet
CRITICAL 10.0
CVE-2026-42933
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active …
Mitigation only
CRITICAL 9.9
CVE-2026-63732
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation…
No fix yet
CRITICAL 10.0
CVE-2025-71389
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Serv…
Patch available
CRITICAL 9.9
CVE-2024-58354
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow p…
Patch available
CRITICAL 9.8
CVE-2026-52439
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
No fix yet