Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-63800
In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RE…
Linux Kernel
5.5 / 5.10.260+
CRITICAL 10.0
CVE-2026-63795
In the Linux kernel, the following vulnerability has been resolved:
9p: avoid putting oldfid in p9_client_walk() error path
When p9_client_walk() i…
Linux Kernel
6.1.177 / 6.6.144+
CRITICAL 9.8
CVE-2026-53399
In the Linux kernel, the following vulnerability has been resolved:
nfsd: release layout stid on setlease failure
nfs4_alloc_stid() publishes the n…
Linux Kernel
5.10.261 / 5.15.212+
CRITICAL 9.8
CVE-2026-53398
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Fix SECINFO_NO_NAME decode error cleanup
nfsd4_decode_secinfo_no_name() c…
Linux Kernel
5.10.260 / 5.15.211+
CRITICAL 9.8
CVE-2026-53384
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
dw8250_p…
Linux Kernel
6.1.177 / 6.6.144+
CRITICAL 10.0
CVE-2026-16117
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's …
Fastify\/http Proxy
11.6.0+
CRITICAL 10.0
CVE-2026-16158
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and …
Fastify\/reply From
12.6.4+
CRITICAL 10.0
CVE-2026-15631
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the confi…
Fastify\/http Proxy
11.6.0+
CRITICAL 9.8
CVE-2026-47865
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control …
Vmware Avi Load Balancer
22.1.7 / 30.2.7+
CRITICAL 9.6
CVE-2026-55518
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_…
Patch available
CRITICAL 9.8
CVE-2026-52348
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
No fix yet
CRITICAL 10.0
CVE-2026-54159
PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected s…
Patch available
CRITICAL 9.8
CVE-2026-48062
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php check…
Patch available
CRITICAL 9.8
CVE-2026-13446
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut…
Langflow
1.10.2+
CRITICAL 9.9
CVE-2026-8859
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat…
Langflow
1.10.1+
CRITICAL 9.9
CVE-2026-8635
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a…
Langflow
1.10.1+
CRITICAL 9.8
CVE-2026-8505
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec…
Langflow
1.10.1+
CRITICAL 9.9
CVE-2026-8481
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va…
Langflow
1.10.1+
CRITICAL 9.9
CVE-2026-8476
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache …
Langflow
1.10.1+
CRITICAL 9.8
CVE-2026-63030 KEVEPSS 98%
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…
WordPress
6.9.5 / 7.0.2+
CRITICAL 9.1
CVE-2026-52199
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
Mitigation only
CRITICAL 9.8
CVE-2026-46420
setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivamma…
Setup Php
2.37.1+
CRITICAL 9.1
CVE-2026-42168
django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passe…
No fix yet
CRITICAL 9.8
CVE-2026-36669
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious…
No fix yet
CRITICAL 9.8
CVE-2026-14501
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th…
Agentics
1.1.3+
CRITICAL 9.3
CVE-2026-15091
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…
Engineering Ai Hub
1.3.0+
CRITICAL 9.8
CVE-2026-13473
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…
Storage Protect
8.2.1.2+
CRITICAL 9.8
CVE-2026-13448
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (…
Langflow
1.10.2+
CRITICAL 9.1
CVE-2025-51677
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead t…
No fix yet
CRITICAL 9.9
CVE-2026-9135
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner…
Langflow
1.10.1+