Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2026-12366
Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its ref…
Patch available
MEDIUM 5.8
CVE-2026-12365
A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work …
Patch available
HIGH 8.4
CVE-2026-12364
The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-sup…
Patch available
MEDIUM 6.5
CVE-2026-73846
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request paramete…
Patch available
MEDIUM 5.3
CVE-2026-73845
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…
Patch available
HIGH 7.1
CVE-2026-49989
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they …
No fix yet
HIGH 7.1
CVE-2026-49986
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` enviro…
No fix yet
MEDIUM 5.1
CVE-2026-47766
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev`…
No fix yet
HIGH 7.5
CVE-2026-46603
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffm…
No fix yet
HIGH 7.8
CVE-2026-46439
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (S…
Patch available
MEDIUM 6.7
CVE-2026-46380
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas…
Patch available
HIGH 8.8
CVE-2026-19845
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.c…
No fix yet
HIGH 8.8
CVE-2026-19844
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi…
No fix yet
HIGH 7.2
CVE-2026-19628
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to …
Security Center
6.9.0+
CRITICAL 9.9
CVE-2026-19626
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …
Security Center
6.9.0+
MEDIUM 5.3
CVE-2026-66272
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate…
Wyse Management Suite
2605.0.2+
HIGH 7.2
CVE-2026-66271
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…
Wyse Management Suite
2605.0.2+
HIGH 7.2
CVE-2026-66270
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…
Wyse Management Suite
2605.0.2+
MEDIUM 5.5
CVE-2026-63702
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with l…
Wyse Management Suite
2605.0.2+
HIGH 7.8
CVE-2026-63701
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged a…
Wyse Management Suite
2605.0.2+
HIGH 7.8
CVE-2026-63700
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with l…
Wyse Management Suite
2605.0.2+
MEDIUM 6.9
CVE-2026-57472
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma…
No fix yet
MEDIUM 6.8
CVE-2026-57471
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma…
No fix yet
MEDIUM 5.1
CVE-2026-57469
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory i…
No fix yet
HIGH 7.5
CVE-2026-53970
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers…
Patch available
HIGH 8.4
CVE-2026-19884
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the fold…
Patch available
HIGH 8.1
CVE-2026-16772
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful…
No fix yet
MEDIUM 5.9
CVE-2026-13198
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …
No fix yet
HIGH 7.3
CVE-2026-13197
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …
No fix yet
HIGH 7.3
CVE-2026-13196
Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in ver…
No fix yet