Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2026-17079
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable serv…
No fix yet
HIGH 7.5
CVE-2026-16915
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
Db2 Mirror For I
after 7.6
MEDIUM 6.5
CVE-2026-16905
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
Db2 Mirror For I
after 7.6
HIGH 8.8
CVE-2026-16879
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization usin…
Db2 Mirror For I
after 7.6
HIGH 8.3
CVE-2026-16708
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
No fix yet
HIGH 7.2
CVE-2026-73679
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute…
No fix yet
CRITICAL 10.0
CVE-2026-73678
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attacke…
No fix yet
MEDIUM 5.3
CVE-2026-50029
js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with…
Patch available
CRITICAL 9.8
CVE-2026-50027
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are…
No fix yet
CRITICAL 9.1
CVE-2026-49457
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak…
No fix yet
HIGH 7.5
CVE-2026-45699
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflo…
No fix yet
CRITICAL 10.0
CVE-2026-19188
A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net…
No fix yet
MEDIUM 6.0
CVE-2026-18403
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that cop…
Patch available
HIGH 7.1
CVE-2025-7639
The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority - Operator" privilege to tamper with serialized
data, p…
No fix yet
HIGH 8.6
CVE-2026-73850
Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.ph…
No fix yet
CRITICAL 9.8
CVE-2026-73849
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately …
No fix yet
MEDIUM 6.8
CVE-2026-73847
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.p…
No fix yet
HIGH 8.3
CVE-2026-72970
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
151.0.4129.86+
HIGH 8.5
CVE-2026-63361
LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text…
Patch available
MEDIUM 5.1
CVE-2026-49282
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs d…
No fix yet
CRITICAL 9.8
CVE-2026-48528
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth…
No fix yet
HIGH 8.8
CVE-2026-19847
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.…
No fix yet
HIGH 8.8
CVE-2026-19846
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi…
No fix yet
CRITICAL 9.9
CVE-2026-19682
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…
Security Center
6.9.0+
CRITICAL 9.9
CVE-2026-19681
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…
Security Center
6.9.0+
HIGH 7.1
CVE-2026-19680
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
Security Center
6.9.0+
HIGH 8.8
CVE-2026-19679
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contr…
Security Center
6.9.0+
MEDIUM 5.3
CVE-2026-19636
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security contro…
Security Center
6.9.0+
HIGH 8.8
CVE-2026-19635
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve ar…
Security Center
6.9.0+
HIGH 8.1
CVE-2026-19629
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission o…
Security Center
6.9.0+