Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2026-73227
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server t…
Patch available
HIGH 8.8
CVE-2026-73226
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSock…
Patch available
HIGH 8.1
CVE-2026-73225
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP …
Patch available
HIGH 8.8
CVE-2026-73224
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP …
Patch available
HIGH 8.1
CVE-2026-73223
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server …
Patch available
HIGH 8.8
CVE-2026-73222
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud…
Patch available
MEDIUM 5.3
CVE-2026-73221
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use…
Patch available
HIGH 8.6
CVE-2026-72742
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over langua…
Patch available
HIGH 8.3
CVE-2026-69119
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or pe…
Patch available
MEDIUM 6.5
CVE-2026-69117
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitr…
Patch available
MEDIUM 6.5
CVE-2026-69115
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints …
Patch available
HIGH 7.5
CVE-2026-48809
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of …
No fix yet
HIGH 7.5
CVE-2026-48802
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation o…
No fix yet
HIGH 8.1
CVE-2026-18712
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio…
No fix yet
HIGH 7.1
CVE-2026-18711
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t…
No fix yet
MEDIUM 6.4
CVE-2026-18709
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa…
No fix yet
MEDIUM 6.4
CVE-2026-18708
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe…
No fix yet
MEDIUM 6.6
CVE-2026-18706
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management command…
No fix yet
MEDIUM 6.5
CVE-2026-18705
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a …
No fix yet
MEDIUM 6.5
CVE-2026-18704
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co…
No fix yet
MEDIUM 6.4
CVE-2026-18702
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe…
No fix yet
MEDIUM 6.5
CVE-2026-18701
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpect…
No fix yet
MEDIUM 6.5
CVE-2026-18700
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used …
No fix yet
MEDIUM 6.5
CVE-2026-18699
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unex…
No fix yet
MEDIUM 5.4
CVE-2026-18698
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
HIGH 7.5
CVE-2026-18697
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly …
No fix yet
MEDIUM 6.5
CVE-2026-18696
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti…
No fix yet
MEDIUM 6.5
CVE-2026-18695
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user …
No fix yet
HIGH 7.1
CVE-2026-18694
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry …
No fix yet
HIGH 7.6
CVE-2026-18693
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data str…
No fix yet