Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2026-18692
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref…
No fix yet
HIGH 8.8
CVE-2026-18691
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…
No fix yet
HIGH 8.1
CVE-2026-18690
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
HIGH 7.1
CVE-2026-18688
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially…
No fix yet
HIGH 7.1
CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection…
No fix yet
HIGH 8.8
CVE-2026-15426
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by…
No fix yet
MEDIUM 5.3
CVE-2026-73219
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT …
Patch available
HIGH 7.7
CVE-2026-73218
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do…
No fix yet
HIGH 7.7
CVE-2026-73217
Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to repla…
No fix yet
MEDIUM 6.5
CVE-2026-73216
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c pre…
Patch available
HIGH 7.1
CVE-2026-73215
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks …
Patch available
HIGH 8.2
CVE-2026-73214
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket…
Patch available
MEDIUM 5.8
CVE-2026-73213
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-…
Patch available
MEDIUM 5.8
CVE-2026-73212
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…
Patch available
CRITICAL 9.8
CVE-2026-73211
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…
Patch available
CRITICAL 9.3
CVE-2026-73090
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…
Patch available
HIGH 7.5
CVE-2026-72713
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitra…
Patch available
MEDIUM 6.5
CVE-2026-72712
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a …
Patch available
CRITICAL 10.0
CVE-2026-71398
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
CRITICAL 9.1
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…
No fix yet
MEDIUM 5.4
CVE-2026-69113
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on…
Patch available
CRITICAL 9.8
CVE-2026-69102
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica…
Patch available
MEDIUM 6.7
CVE-2026-65680
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Onedrive
26.095.0519.0003+
MEDIUM 5.5
CVE-2026-48790
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s…
Patch available
HIGH 8.2
CVE-2026-48771
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien…
No fix yet
HIGH 7.6
CVE-2026-48767
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth ac…
Patch available
HIGH 7.1
CVE-2026-48494
TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook …
Patch available
HIGH 7.7
CVE-2026-48447
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…
Lightroom
15.5+
HIGH 8.6
CVE-2026-48441
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a…
Lightroom
15.5+
HIGH 7.5
CVE-2026-48416
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
No fix yet