Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-53785
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory t…
No fix yet
HIGH 7.1
CVE-2026-53784
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroo…
No fix yet
HIGH 8.1
CVE-2026-53783
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows a…
No fix yet
HIGH 7.4
CVE-2026-49857
auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `asse…
Patch available
HIGH 7.1
CVE-2026-28154
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerc…
No fix yet
HIGH 8.6
CVE-2026-19734
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4…
Patch available
HIGH 8.8
CVE-2026-19293
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
mak…
No fix yet
HIGH 8.8
CVE-2026-19292
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linke…
No fix yet
HIGH 8.8
CVE-2026-19291
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
No fix yet
HIGH 8.8
CVE-2026-16101
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
No fix yet
HIGH 7.0
CVE-2026-15994
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that …
No fix yet
HIGH 7.5
CVE-2026-14456
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can …
Patch available
HIGH 7.1
CVE-2026-12036
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a loc…
No fix yet
MEDIUM 5.3
CVE-2026-73403
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73401
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73357
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73353
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73349
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
No fix yet
HIGH 7.6
CVE-2026-73346
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
No fix yet
MEDIUM 5.9
CVE-2026-73344
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73340
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
No fix yet
HIGH 7.5
CVE-2026-73188
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
No fix yet
HIGH 7.5
CVE-2026-67991
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLL…
No fix yet
MEDIUM 5.4
CVE-2026-67990
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controll…
No fix yet
HIGH 8.4
CVE-2026-67986
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A…
No fix yet
HIGH 7.2
CVE-2026-66704
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
No fix yet
HIGH 7.1
CVE-2026-66700
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
No fix yet
HIGH 7.1
CVE-2026-66698
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
No fix yet
HIGH 7.1
CVE-2026-66697
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66693
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
No fix yet