Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.2
CVE-2026-74243
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…
Openshift Update Service
No fix yet
MEDIUM 5.3
CVE-2026-74242
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U…
No fix yet
MEDIUM 5.4
CVE-2026-74240
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple iss…
Openshift Update Service
No fix yet
HIGH 8.1
CVE-2026-73683
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC i…
Patch available
HIGH 7.8
CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "Shield…
Malware Protection Engine
No fix yet
HIGH 8.8
CVE-2026-73682
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows…
Patch available
MEDIUM 5.1
CVE-2026-71570
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_ic…
No fix yet
MEDIUM 5.3
CVE-2026-67366
Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the fronte…
No fix yet
HIGH 7.8
CVE-2026-50523
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute …
Powershell
7.4.19.0 / 7.5.10.0+
HIGH 8.8
CVE-2026-73680
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the asset…
Patch available
HIGH 8.6
CVE-2026-71571
Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permi…
No fix yet
CRITICAL 9.2
CVE-2026-67365
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (…
No fix yet
HIGH 7.0
CVE-2026-64887
Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.
This issue affects Airwall: before 4.1.
No fix yet
HIGH 7.0
CVE-2026-34492
External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation.
This issue affects Airwall: before 4.1.
No fix yet
HIGH 7.5
CVE-2026-19910
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacen…
No fix yet
HIGH 7.5
CVE-2026-19909
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…
No fix yet
HIGH 7.1
CVE-2026-19908
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive inform…
No fix yet
HIGH 7.5
CVE-2026-18554
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pa…
Db2 Mirror For I
after 7.6
HIGH 8.1
CVE-2026-18178
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Db2 Mirror For I
after 7.6
MEDIUM 6.5
CVE-2026-17227
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of …
Db2 Mirror For I
after 7.6
MEDIUM 5.4
CVE-2026-17209
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
Db2 Mirror For I
after 7.6
CRITICAL 9.8
CVE-2026-17186
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…
Db2 Mirror For I
after 7.6
CRITICAL 9.8
CVE-2026-17184
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
Db2 Mirror For I
after 7.6
CRITICAL 9.8
CVE-2026-17182
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp…
Db2 Mirror For I
after 7.6
HIGH 8.6
CVE-2026-17181
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Db2 Mirror For I
after 7.6
MEDIUM 6.5
CVE-2026-17179
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
Db2 Mirror For I
after 7.6
HIGH 7.5
CVE-2026-17177
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
Db2 Mirror For I
after 7.6
MEDIUM 6.5
CVE-2026-17175
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enf…
Db2 Mirror For I
after 7.6
MEDIUM 6.5
CVE-2026-17173
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file…
Db2 Mirror For I
after 7.6
HIGH 7.5
CVE-2026-17081
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricte…
Db2 Mirror For I
after 7.6