Exploited in the wildLatest CVEs on the CISA KEV list
HIGH 7.0
CVE-2026-68820
Windows 10 1607
HIGH 8.6
CVE-2026-20349
Adaptive Security Appliance Software
CRITICAL 10.0
CVE-2026-72898
Metabase
CRITICAL 9.8
CVE-2026-65400
macOS
HIGH 8.1
CVE-2026-18577
N Central
HIGH 7.4
CVE-2026-18556
N Central
CRITICAL 9.8
CVE-2026-59310
Vcenter Server
MEDIUM 5.3
CVE-2026-20316
Secure Firewall Management Center
Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2026-76050
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?acti…
Fix unknown
HIGH 7.3
CVE-2026-76049
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php…
Fix unknown
HIGH 7.3
CVE-2026-76048
A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.p…
Fix unknown
CRITICAL 10.0
CVE-2026-76008
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…
Fix unknown
CRITICAL 9.9
CVE-2026-76004
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th…
Fix unknown
CRITICAL 9.9
CVE-2026-76003
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing…
Fix unknown
HIGH 7.3
CVE-2026-75987
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/sc…
Fix unknown
HIGH 7.3
CVE-2026-75986
A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of…
Fix unknown
HIGH 7.4
CVE-2026-75985
A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of t…
Fix unknown
MEDIUM 6.4
CVE-2026-15421
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attr…
Fix unknown
CRITICAL 9.1
CVE-2026-11751
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow…
Fix unknown
HIGH 7.4
CVE-2026-75984
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of th…
Fix unknown
MEDIUM 6.3
CVE-2026-75979
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerCo…
Fix unknown
MEDIUM 6.3
CVE-2026-75978
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController…
Fix unknown
CRITICAL 9.9
CVE-2026-75976
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM.…
Fix unknown
MEDIUM 6.5
CVE-2026-66591
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows St…
Fix unknown
MEDIUM 5.4
CVE-2026-66589
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue aff…
Fix unknown
MEDIUM 5.9
CVE-2026-27365
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored …
Fix unknown
MEDIUM 5.5
CVE-2026-73974
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses …
Fix unknown
MEDIUM 5.5
CVE-2026-73973
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/log…
Fix unknown
MEDIUM 6.5
CVE-2026-66603
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allow…
Fix unknown
HIGH 8.8
CVE-2026-66602
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affec…
Fix unknown
HIGH 8.7
CVE-2026-62292
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-…
Fix unknown
MEDIUM 5.3
CVE-2026-62291
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 au…
Fix unknown
MEDIUM 6.5
CVE-2026-53959
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account informatio…
Fix unknown
HIGH 7.6
CVE-2026-53958
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogle…
Fix unknown
HIGH 8.3
CVE-2026-52877
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in sr…
Fix unknown
HIGH 8.8
CVE-2026-52876
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler i…
Fix unknown
HIGH 8.4
CVE-2026-52875
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in…
Fix unknown
MEDIUM 6.9
CVE-2026-52873
Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-rede…
Fix unknown