Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-19518
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.
Patch available
MEDIUM 6.5
CVE-2026-19517
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlot…
Patch available
MEDIUM 6.5
CVE-2026-19391
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th…
No fix yet
HIGH 8.5
CVE-2026-16053
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch…
No fix yet
MEDIUM 5.3
CVE-2026-8158
The Signed Video Framework contained a buffer overflow issue
which could lead the application using this framework to crash. The issue exclusively …
No fix yet
MEDIUM 5.1
CVE-2026-6505
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…
No fix yet
MEDIUM 5.9
CVE-2026-6181
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer…
No fix yet
MEDIUM 5.7
CVE-2026-5304
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …
No fix yet
MEDIUM 5.7
CVE-2026-5303
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…
No fix yet
HIGH 7.2
CVE-2026-4757
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…
No fix yet
MEDIUM 6.5
CVE-2026-14548
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…
No fix yet
CRITICAL 9.1
CVE-2026-19516
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…
No fix yet
CRITICAL 9.1
CVE-2026-13716
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path…
Crafty Controller
4.10.8+
MEDIUM 5.2
CVE-2026-12052
The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size respons…
Patch available
MEDIUM 5.9
CVE-2026-11894
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-own…
Patch available
CRITICAL 9.8
CVE-2026-19425
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…
No fix yet
MEDIUM 6.4
CVE-2026-16974
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…
No fix yet
MEDIUM 5.9
CVE-2026-11893
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates t…
Patch available
HIGH 8.4
CVE-2026-8917
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe…
No fix yet
MEDIUM 6.5
CVE-2026-24330
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…
No fix yet
HIGH 7.5
CVE-2026-19424
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp…
No fix yet
MEDIUM 6.3
CVE-2026-66779
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…
No fix yet
MEDIUM 5.3
CVE-2026-66778
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…
No fix yet
MEDIUM 5.9
CVE-2026-66777
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…
No fix yet
MEDIUM 5.9
CVE-2026-66776
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …
No fix yet
MEDIUM 5.9
CVE-2026-66773
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma…
No fix yet
MEDIUM 6.1
CVE-2026-66771
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …
No fix yet
MEDIUM 6.3
CVE-2026-66770
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…
No fix yet
HIGH 7.9
CVE-2026-66763
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic…
No fix yet
MEDIUM 6.4
CVE-2026-66760
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …
No fix yet