Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-47767
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.1…
Symfony
5.4.52 / 6.4.40+
CRITICAL 9.8
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
.net Framework
8.0.29 / 9.0.18+
CRITICAL 9.1
CVE-2026-45069
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandl…
Symfony
6.4.40 / 7.4.12+
CRITICAL 9.1
CVE-2026-45063
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Au…
Symfony
5.4.52 / 6.4.40+
CRITICAL 9.8
CVE-2026-58617
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
2.111.4+
CRITICAL 9.8
CVE-2026-58594
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.9
CVE-2026-57092
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-57090
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-57089
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-56159
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-55944
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Dynamics Nav
Patch available
CRITICAL 9.1
CVE-2026-55040 KEVEPSS 6%
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-55010
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
Minecraft Bedrock Dedicated Server
No fix yet
CRITICAL 9.8
CVE-2026-50518
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50487
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
CRITICAL 9.8
CVE-2026-50447
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50439
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.6
CVE-2026-50380
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50330
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.1
CVE-2026-15747
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.
_csrf_t…
Patch available
CRITICAL 9.6
CVE-2026-59891
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the…
Patch available
CRITICAL 9.8
CVE-2026-58644 KEVEPSS 16%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-56164 KEVEPSS 27%
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.6
CVE-2026-55008
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …
Exchange Server
15.02.2562.045+
CRITICAL 9.8
CVE-2026-54995
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 10.0
CVE-2026-54433
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The att…
Webmail
1.6.17 / 1.7.2+
CRITICAL 9.8
CVE-2026-54118
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Sql Server 2016
13.0.6500.1 / 13.0.7095.1+
CRITICAL 9.8
CVE-2026-54117
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Sql Server 2016
13.0.6500.1 / 13.0.7095.1+
CRITICAL 9.1
CVE-2026-54058
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec p…
Pillow
12.3.0+