Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.9
CVE-2026-47724
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust…
Patch available
CRITICAL 9.8
CVE-2026-15981
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is …
No fix yet
CRITICAL 9.9
CVE-2026-15630
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…
No fix yet
CRITICAL 9.8
CVE-2026-15967
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before…
Moveit Transfer
2025.1.5 / 2026.0.3+
CRITICAL 9.8
CVE-2026-15966
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before…
Moveit Transfer
2025.1.5 / 2026.0.3+
CRITICAL 9.8
CVE-2026-10697
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.…
Moveit Transfer
2025.1.5 / 2026.0.3+
CRITICAL 9.8
CVE-2026-63359
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra…
Mitigation only
CRITICAL 9.4
CVE-2026-47670
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …
No fix yet
CRITICAL 9.3
CVE-2026-47669
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`…
No fix yet
CRITICAL 10.0
CVE-2026-6516
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
No fix yet
CRITICAL 9.1
CVE-2026-65701
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una…
No fix yet
CRITICAL 9.8
CVE-2026-65700
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…
No fix yet
CRITICAL 9.9
CVE-2026-47752
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection…
No fix yet
CRITICAL 10.0
CVE-2026-47668
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…
No fix yet
CRITICAL 9.9
CVE-2026-44210
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. V…
Kata Containers
3.31.0+
CRITICAL 9.3
CVE-2026-65761
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead …
No fix yet
CRITICAL 9.2
CVE-2026-65760
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch…
No fix yet
CRITICAL 9.1
CVE-2026-15617
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via ca…
No fix yet
CRITICAL 9.1
CVE-2026-15616
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized …
No fix yet
CRITICAL 9.1
CVE-2026-15612
Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session…
No fix yet
CRITICAL 9.1
CVE-2026-15611
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and …
No fix yet
CRITICAL 9.8
CVE-2026-65689
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all…
Standalone Report Designer
14.1.12+
CRITICAL 9.8
CVE-2026-65688
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow…
Standalone Report Designer
14.1.12+
CRITICAL 9.8
CVE-2026-65687
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows…
Standalone Report Designer
14.1.12+
CRITICAL 9.1
CVE-2026-65907
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
No fix yet
CRITICAL 10.0
CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Teamcity
2025.11.6 / 2026.1.2+
CRITICAL 9.6
CVE-2026-65606
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references …
Patch available
CRITICAL 9.6
CVE-2026-65605
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren…
Patch available
CRITICAL 9.6
CVE-2026-65471
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
Mitigation only
CRITICAL 9.1
CVE-2026-65461
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Mitigation only