Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2025-14600
An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application …
No fix yet
CRITICAL 9.8
CVE-2026-75143
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size arg…
No fix yet
CRITICAL 9.0
CVE-2026-72530 KEV
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, …
Trueconf Server
5.3.9.10013 / 5.3.9.10015+
CRITICAL 9.8
CVE-2026-72529 KEV
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, …
Trueconf Server
5.3.9.10013 / 5.3.9.10015+
CRITICAL 9.1
CVE-2026-71470
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Se…
No fix yet
CRITICAL 9.1
CVE-2026-49441
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged…
Patch available
CRITICAL 9.1
CVE-2026-48162
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI…
Patch available
CRITICAL 9.1
CVE-2026-48024
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerg…
Patch available
CRITICAL 9.9
CVE-2026-20359
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive i…
No fix yet
CRITICAL 10.0
CVE-2026-20358
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive i…
No fix yet
CRITICAL 10.0
CVE-2026-20357
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive i…
No fix yet
CRITICAL 9.6
CVE-2026-20318
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehen…
No fix yet
CRITICAL 10.0
CVE-2026-20317
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehen…
No fix yet
CRITICAL 10.0
CVE-2026-20315
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehen…
No fix yet
CRITICAL 9.9
CVE-2026-20231
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehen…
No fix yet
CRITICAL 10.0
CVE-2026-20030
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive i…
No fix yet
CRITICAL 9.4
CVE-2026-62668
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookC…
Patch available
CRITICAL 9.3
CVE-2026-75954
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated int…
No fix yet
CRITICAL 10.0
CVE-2026-75949
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a clien…
No fix yet
CRITICAL 9.1
CVE-2026-71960
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authenticat…
No fix yet
CRITICAL 9.8
CVE-2026-53451
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the…
Patch available
CRITICAL 9.8
CVE-2026-52889
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Refe…
Patch available
CRITICAL 9.3
CVE-2026-47187
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets o…
Patch available
CRITICAL 9.4
CVE-2026-45272
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post han…
Patch available
CRITICAL 9.9
CVE-2026-16816
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralizatio…
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.8
CVE-2026-16656
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.9
CVE-2026-15068
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutraliz…
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.1
CVE-2026-15065
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate c…
Vios
4.1.0.50 / 4.1.1.30+
CRITICAL 9.1
CVE-2026-76244
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection whe…
No fix yet
CRITICAL 9.2
CVE-2026-76243
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read,…
No fix yet