Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-73567
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.…
Patch available
HIGH 7.5
CVE-2026-73566
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper t…
Patch available
MEDIUM 5.3
CVE-2026-73565
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w…
Patch available
HIGH 8.7
CVE-2026-73564
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by a…
Patch available
MEDIUM 6.5
CVE-2026-73562
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a us…
Patch available
HIGH 7.5
CVE-2026-73561
Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadD…
Patch available
HIGH 8.1
CVE-2026-72741
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth…
No fix yet
CRITICAL 9.8
CVE-2026-67614
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…
No fix yet
HIGH 8.8
CVE-2026-18428
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query …
No fix yet
MEDIUM 6.5
CVE-2026-12236
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from …
Patch available
HIGH 7.5
CVE-2024-58374
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke…
No fix yet
HIGH 7.5
CVE-2019-25765
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b…
No fix yet
HIGH 7.1
CVE-2026-73266
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by ma…
No fix yet
HIGH 7.5
CVE-2026-59765
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
No fix yet
HIGH 8.8
CVE-2026-59109
SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a rece…
No fix yet
CRITICAL 9.1
CVE-2026-58508
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
No fix yet
MEDIUM 5.3
CVE-2026-58507
Private Repository Existence Disclosure via go-get Meta Endpoint
No fix yet
CRITICAL 9.1
CVE-2026-58443
Public-only repository tokens can update private PR head branches
No fix yet
MEDIUM 6.5
CVE-2026-58442
Repository migration SSRF via multi-answer DNS allow-list bypass
No fix yet
MEDIUM 6.3
CVE-2026-58441
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
No fix yet
MEDIUM 6.8
CVE-2026-58440
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet…
No fix yet
HIGH 8.1
CVE-2026-58439
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
No fix yet
HIGH 7.5
CVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
No fix yet
HIGH 7.1
CVE-2026-58437
Repository Visibility Manipulation via Git Push Options
No fix yet
HIGH 7.5
CVE-2026-58436
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
No fix yet
MEDIUM 5.4
CVE-2026-58435
Gitea LFS Deploy-Key Privilege Escalation
No fix yet
HIGH 7.5
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
No fix yet
CRITICAL 9.1
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
MEDIUM 6.5
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
No fix yet