Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2026-19002
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write …
No fix yet
CRITICAL 9.8
CVE-2026-19001
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, sche…
No fix yet
MEDIUM 6.5
CVE-2026-18888
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buf…
No fix yet
HIGH 7.1
CVE-2026-16480
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a no…
Db2
after 12.1.5
MEDIUM 5.5
CVE-2026-18097
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to ob…
Db2
after 12.1.5
CRITICAL 9.8
CVE-2026-17616
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…
Security Verify Access
10.0.9.2 / 11.0.3+
HIGH 7.8
CVE-2026-16695
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci…
I Access Client Solutions
1.1.9.14+
HIGH 8.5
CVE-2026-16033
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me…
No fix yet
HIGH 7.1
CVE-2026-14866
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
I Access Client Solutions
1.1.9.14+
HIGH 8.8
CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside…
No fix yet
HIGH 7.3
CVE-2026-13476
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges …
Informix Dynamic Server
15.0.1.13+
CRITICAL 9.6
CVE-2026-13433
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an I…
I Access Client Solutions
1.1.9.14+
HIGH 7.8
CVE-2026-13367
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
Informix Dynamic Server
No fix yet
HIGH 8.8
CVE-2026-13105
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
I Access Client Solutions
1.1.9.14+
HIGH 7.8
CVE-2026-13094
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi…
I Access Client Solutions
1.1.9.14+
HIGH 7.5
CVE-2026-11932
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…
Security Verify Access
after 11.0.3
CRITICAL 9.8
CVE-2026-10543
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
Db2
after 12.1.5
MEDIUM 6.1
CVE-2026-73434
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc…
Enterprise Linux
1.28.6+
MEDIUM 6.6
CVE-2026-73433
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements…
Enterprise Linux
after 1.28.6
HIGH 7.5
CVE-2026-73415
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4…
Patch available
CRITICAL 9.2
CVE-2026-73414
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`…
Patch available
HIGH 8.7
CVE-2026-73413
Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/com…
Patch available
MEDIUM 6.3
CVE-2026-73412
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly c…
Patch available
MEDIUM 6.3
CVE-2026-73411
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~…
Patch available
MEDIUM 5.1
CVE-2026-73409
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKe…
Patch available
CRITICAL 9.0
CVE-2026-73407
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials …
Patch available
HIGH 7.5
CVE-2026-73406
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/sr…
Patch available
HIGH 8.7
CVE-2026-73332
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t…
No fix yet
HIGH 7.1
CVE-2026-73331
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges …
No fix yet
MEDIUM 6.6
CVE-2026-73330
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by e…
No fix yet