Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-66340
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login a…
No fix yet
MEDIUM 6.5
CVE-2026-66098
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload…
No fix yet
CRITICAL 9.6
CVE-2026-5917
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all…
No fix yet
HIGH 7.5
CVE-2026-29036
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within c…
No fix yet
HIGH 8.8
CVE-2026-19560
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
151.0.7922.137+
HIGH 8.8
CVE-2026-19559
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
151.0.7922.137+
HIGH 7.5
CVE-2026-19558
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to ex…
Chrome
151.0.7922.137+
HIGH 8.3
CVE-2026-19557
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to pote…
Chrome
151.0.7922.137+
HIGH 8.8
CVE-2026-19556
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
151.0.7922.137+
MEDIUM 6.5
CVE-2026-18710
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica…
No fix yet
CRITICAL 9.1
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…
Httpclient
5.6.4+
MEDIUM 6.5
CVE-2026-66832
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query s…
No fix yet
HIGH 8.3
CVE-2026-66154
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie…
No fix yet
HIGH 7.8
CVE-2026-66150
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
HIGH 7.8
CVE-2026-66149
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
MEDIUM 6.3
CVE-2026-66148
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…
No fix yet
CRITICAL 9.4
CVE-2026-66147
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…
No fix yet
HIGH 7.1
CVE-2026-63177
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…
No fix yet
MEDIUM 5.4
CVE-2026-63134
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…
No fix yet
MEDIUM 6.5
CVE-2026-63133
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count…
No fix yet
HIGH 8.8
CVE-2026-55676
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…
No fix yet
CRITICAL 9.9
CVE-2026-48765
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from…
Patch available
HIGH 8.2
CVE-2026-48763
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b…
Patch available
MEDIUM 5.4
CVE-2026-48762
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using …
Patch available
HIGH 8.2
CVE-2026-19550
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio…
No fix yet
MEDIUM 6.5
CVE-2026-29035
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot…
No fix yet
MEDIUM 5.4
CVE-2026-19579
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The ca…
Snipe It
8.6.0+
HIGH 8.4
CVE-2026-18634
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…
No fix yet
HIGH 8.8
CVE-2026-15606
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…
No fix yet
HIGH 8.8
CVE-2026-14863
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod…
No fix yet