Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.0
CVE-2026-73488
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo…
No fix yet
CRITICAL 9.0
CVE-2026-73487
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…
No fix yet
CRITICAL 9.0
CVE-2026-73486
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…
No fix yet
CRITICAL 9.0
CVE-2026-73485
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…
No fix yet
HIGH 8.6
CVE-2026-73484
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_cs…
No fix yet
CRITICAL 9.4
CVE-2026-73483
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…
No fix yet
MEDIUM 6.6
CVE-2026-45819
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immed…
Patch available
MEDIUM 6.0
CVE-2026-18368
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd
due to improper handling of Modbus TCP request data. A remote,
unauthentic…
No fix yet
MEDIUM 6.9
CVE-2026-16455
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exis…
No fix yet
HIGH 8.8
CVE-2026-12263
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi…
No fix yet
CRITICAL 9.3
CVE-2026-59507
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
No fix yet
CRITICAL 9.3
CVE-2026-59506
CWE-306: Missing Authentication for Critical Function
No fix yet
HIGH 8.6
CVE-2026-59505
CWE-284: Improper Access Control
No fix yet
CRITICAL 9.1
CVE-2026-59504
CWE-602: Client-Side Enforcement of Server-Side Security
No fix yet
CRITICAL 9.1
CVE-2026-59503
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
No fix yet
MEDIUM 5.3
CVE-2026-59502
CWE-203: Observable Discrepancy
No fix yet
HIGH 8.2
CVE-2026-59501
CWE-284: Improper Access Control
No fix yet
CRITICAL 10.0
CVE-2026-59500
CWE-287: Improper Authentication
No fix yet
HIGH 8.6
CVE-2026-59499
CWE-200: Exposure of Sensitive
Information to an Unauthorized Actor
No fix yet
HIGH 7.5
CVE-2026-19484
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop …
No fix yet
MEDIUM 6.6
CVE-2026-19696
Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
No fix yet
HIGH 7.5
CVE-2026-19481
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser…
No fix yet
MEDIUM 5.9
CVE-2026-16459
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an att…
No fix yet
MEDIUM 5.9
CVE-2026-16458
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to r…
No fix yet
CRITICAL 10.0
CVE-2026-15413
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp…
No fix yet
MEDIUM 5.4
CVE-2026-14332
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its…
No fix yet
MEDIUM 6.5
CVE-2026-14298
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when proces…
Mattermost Server
10.11.23 / 11.7.8+
MEDIUM 6.4
CVE-2026-3639
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in a…
No fix yet
HIGH 8.8
CVE-2026-11840
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj…
No fix yet
HIGH 7.2
CVE-2026-18146
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…
No fix yet