Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2026-53996
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i…
No fix yet
MEDIUM 6.5
CVE-2026-47226
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can…
No fix yet
CRITICAL 9.8
CVE-2026-26035
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…
No fix yet
MEDIUM 5.4
CVE-2026-70560
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attacke…
No fix yet
HIGH 8.1
CVE-2026-70465
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClien…
No fix yet
MEDIUM 5.3
CVE-2026-17008
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and …
No fix yet
MEDIUM 5.3
CVE-2026-16990
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-suppli…
No fix yet
MEDIUM 6.5
CVE-2026-16747
The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input th…
No fix yet
MEDIUM 5.3
CVE-2026-16621
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an orde…
No fix yet
MEDIUM 5.3
CVE-2026-15213
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback:…
No fix yet
MEDIUM 6.5
CVE-2026-15045
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored…
No fix yet
HIGH 8.8
CVE-2026-11325
Description
Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execu…
No fix yet
MEDIUM 6.5
CVE-2026-68868
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Varia…
Apache Airflow Providers Google
22.3.0+
MEDIUM 5.3
CVE-2026-67284
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario…
No fix yet
MEDIUM 6.1
CVE-2026-64955
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. …
No fix yet
MEDIUM 6.5
CVE-2026-64952
The hunt_delete() VQL function allows deleting hunts.
Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned …
No fix yet
MEDIUM 5.9
CVE-2026-18663
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control…
No fix yet
MEDIUM 6.9
CVE-2026-67283
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var…
No fix yet
CRITICAL 10.0
CVE-2026-67282
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code …
No fix yet
HIGH 7.5
CVE-2026-19566
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths.
The _encode method …
Patch available
HIGH 8.2
CVE-2026-19426
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the syst…
No fix yet
HIGH 7.5
CVE-2025-41770
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt acc…
No fix yet
CRITICAL 9.8
CVE-2025-41769
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote atta…
No fix yet
CRITICAL 9.3
CVE-2026-66659
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject…
No fix yet
HIGH 8.1
CVE-2026-19594
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation thro…
No fix yet
MEDIUM 5.4
CVE-2026-19217
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, w…
No fix yet
MEDIUM 5.3
CVE-2026-19073
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and…
No fix yet
MEDIUM 6.4
CVE-2026-19050
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requ…
No fix yet
MEDIUM 6.5
CVE-2026-18943
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low …
No fix yet
HIGH 7.5
CVE-2026-18789
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated atta…
No fix yet