Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-48495
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trus…
Patch available
HIGH 7.1
CVE-2026-42142
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate worksp…
Patch available
HIGH 8.8
CVE-2026-19546
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.
For a detailed Statement, Description and Mit…
No fix yet
HIGH 7.1
CVE-2026-18640
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook …
No fix yet
HIGH 7.3
CVE-2026-18639
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change…
No fix yet
MEDIUM 6.5
CVE-2026-18638
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by c…
No fix yet
MEDIUM 5.3
CVE-2026-14180
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding…
No fix yet
CRITICAL 9.3
CVE-2025-31114
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use…
Patch available
MEDIUM 6.7
CVE-2026-73067
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_sq…
Patch available
MEDIUM 6.8
CVE-2026-73066
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause…
Patch available
MEDIUM 6.1
CVE-2026-72925
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson…
Patch available
HIGH 8.2
CVE-2026-72922
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's…
Patch available
HIGH 8.1
CVE-2026-72921
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.…
Patch available
CRITICAL 9.8
CVE-2026-72920
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory auth…
Patch available
CRITICAL 9.1
CVE-2026-47702
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the …
Patch available
HIGH 8.7
CVE-2026-18860
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other ten…
Patch available
MEDIUM 6.8
CVE-2026-18636
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or…
No fix yet
HIGH 7.2
CVE-2026-18635
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, t…
No fix yet
HIGH 8.1
CVE-2026-18129
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attack…
No fix yet
HIGH 7.7
CVE-2026-18127
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write contr…
No fix yet
HIGH 7.5
CVE-2026-18125
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent serv…
No fix yet
MEDIUM 6.2
CVE-2026-17535
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS ima…
No fix yet
CRITICAL 10.0
CVE-2026-17061
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthen…
No fix yet
MEDIUM 5.1
CVE-2026-73210
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled.
Playwrigh…
Patch available
CRITICAL 9.8
CVE-2026-51584
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route…
No fix yet
HIGH 8.5
CVE-2026-51583
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation …
No fix yet
CRITICAL 10.0
CVE-2026-48056
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat…
No fix yet
CRITICAL 9.3
CVE-2026-48046
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater…
No fix yet
CRITICAL 9.8
CVE-2026-46670
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat…
No fix yet
HIGH 8.6
CVE-2026-19539
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated use…
Patch available