Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-7663
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…
Langflow
1.10.0+
CRITICAL 10.0
CVE-2026-13773EPSS 6%
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…
Websphere Extreme Scale
after 8.6.1.6
CRITICAL 9.9
CVE-2026-13772
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in…
Websphere Extreme Scale
after 8.6.1.6
CRITICAL 9.1
CVE-2026-13449
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …
Business Automation Manager
9.5.0+
CRITICAL 9.8
CVE-2026-11714
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
Websphere Application Server
26.0.0.8+
CRITICAL 9.3
CVE-2026-11712
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.3
CVE-2026-11708
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-11546
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…
Websphere Application Server
26.0.0.8+
CRITICAL 9.1
CVE-2026-10560
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti…
Langflow
after 1.9.6
CRITICAL 9.6
CVE-2026-10140
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A…
Langflow
after 1.10.0
CRITICAL 10.0
CVE-2026-10134
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…
Langflow
after 1.9.3
CRITICAL 9.8
CVE-2026-10109
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
Db2
after 12.1.4
CRITICAL 9.8
CVE-2026-58138EPSS 9%
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitra…
Patch available
CRITICAL 9.1
CVE-2026-58172
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based ac…
Patch available
CRITICAL 9.1
CVE-2026-58166
OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write…
Patch available
CRITICAL 9.3
CVE-2026-48315
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 9.3
CVE-2026-48313
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48286
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi…
Campaign
after 7.4.3
CRITICAL 10.0
CVE-2026-48283
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48281
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48277
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48276
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48282 KEVEPSS 42%
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2026-14241
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…
Firefox
Mitigation only
CRITICAL 9.8
CVE-2026-8655
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service …
Netscaler Application Delivery Controller
13.1-37.272 / 13.1-63.18+
CRITICAL 9.8
CVE-2026-8452
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applian…
Netscaler Application Delivery Controller
13.1-37.272 / 13.1-63.18+
CRITICAL 9.1
CVE-2026-6556
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string …
Fastify\/express
4.0.7+
CRITICAL 9.1
CVE-2026-58016
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo…
Enterprise Linux
2.88.1+
CRITICAL 9.8
CVE-2026-8402
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer In…
Mitigation only
CRITICAL 9.3
CVE-2026-53690
An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ap…
Mitigation only