Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-50694
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50522 KEVEPSS 85%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.3
CVE-2026-49798
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-49181
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-49172
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-49164
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-42990
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-15701
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.…
Mitigation only
CRITICAL 9.8
CVE-2026-62644
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session …
Webmail
1.6.17 / 1.7.2+
CRITICAL 10.0
CVE-2026-62643
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…
Webmail
1.6.17 / 1.7.2+
CRITICAL 9.1
CVE-2026-60082
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source …
Patch available
CRITICAL 9.8
CVE-2026-59836
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…
Forticlientems
7.4.6+
CRITICAL 9.1
CVE-2026-55954
Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.
The Ueberauth.…
Patch available
CRITICAL 9.2
CVE-2025-11698
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a m…
Mitigation only
CRITICAL 9.8
CVE-2026-58479
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allow…
Sustainable Irrigation Platform
after 5.2.16
CRITICAL 9.1
CVE-2026-15265
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende…
Mitigation only
CRITICAL 9.1
CVE-2026-10672
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PA…
Zephyr
Patch available
CRITICAL 9.2
CVE-2025-12012
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file dat…
Mitigation only
CRITICAL 9.2
CVE-2025-12011
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, caus…
Mitigation only
CRITICAL 9.8
CVE-2026-62392
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…
Kylin
5.0.4+
CRITICAL 9.8
CVE-2026-62390
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…
Kylin
5.0.4+
CRITICAL 10.0
CVE-2026-10577
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce…
Mitigation only
CRITICAL 9.8
CVE-2026-62422
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct…
Youtrack
2024.2.148429 / 2024.3.148430+
CRITICAL 9.1
CVE-2026-58319
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …
Doris
3.1.0+
CRITICAL 10.0
CVE-2026-56451
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in t…
Mitigation only
CRITICAL 9.1
CVE-2026-3014
Milestone
has released a new version of XProtect® (and several cumulative patch updates)
which fix security vulnerability in Management Server API.
…
Mitigation only
CRITICAL 9.8
CVE-2026-15043
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.
DBI::SQL::Nano, DBI's built-in mini-SQL engin…
Patch available
CRITICAL 9.1
CVE-2026-59084
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea…
Tomcat
after 11.0.23
CRITICAL 9.1
CVE-2026-59083
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura…
Tomcat
after 11.0.23