Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-65432
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-64958
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-57819
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, …
Cxf
3.6.12 / 4.1.8+
HIGH 8.1
CVE-2026-57817
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-54225
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …
Cxf
3.6.12 / 4.1.8+
HIGH 7.2
CVE-2026-19034
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimit…
No fix yet
MEDIUM 5.5
CVE-2026-55980
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service cond…
No fix yet
MEDIUM 5.2
CVE-2026-55979
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is l…
No fix yet
HIGH 8.4
CVE-2026-55978
An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter co…
No fix yet
MEDIUM 6.5
CVE-2026-64640
Apache Polaris did not consistently validate storage locations supplied during table and view registration.
An authenticated principal with permissi…
Polaris
after 1.6.0
MEDIUM 6.3
CVE-2026-19022
A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pu…
No fix yet
HIGH 7.8
CVE-2026-64601
In the Linux kernel, the following vulnerability has been resolved:
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor …
No fix yet
HIGH 7.8
CVE-2026-64599
In the Linux kernel, the following vulnerability has been resolved:
crypto: amlogic - avoid double cleanup in meson_crypto_probe()
When meson_alloc…
No fix yet
HIGH 8.8
CVE-2026-64598
In the Linux kernel, the following vulnerability has been resolved:
smb/client: Fix error code in smb2_aead_req_alloc()
The "*num_sgs" variable is …
No fix yet
CRITICAL 9.8
CVE-2026-64597
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_close() replay
A response-bearing attempt …
No fix yet
HIGH 7.8
CVE-2026-64588
In the Linux kernel, the following vulnerability has been resolved:
fuse-uring: fix data races on ring->ready
On weakly-ordered architectures, the …
No fix yet
HIGH 7.0
CVE-2026-64587
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
Normal RX/TX…
No fix yet
HIGH 8.8
CVE-2026-64586
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: drain bus_reset work on device removal
brcmf_fw_crashed() and t…
No fix yet
HIGH 7.8
CVE-2026-64585
In the Linux kernel, the following vulnerability has been resolved:
can: esd_usb: kill anchored URBs before freeing netdevs
esd_usb_disconnect() fr…
No fix yet
HIGH 7.8
CVE-2026-64584
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
The …
No fix yet
HIGH 7.8
CVE-2026-64583
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
The …
No fix yet
CRITICAL 10.0
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…
Api Control Plane
4.1.0.257 / 4.2.0.197+
CRITICAL 9.8
CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitati…
Api Control Plane
4.0.0.384 / 4.1.0.248+
HIGH 7.3
CVE-2026-19021
A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown funct…
No fix yet
MEDIUM 6.3
CVE-2026-19020
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file…
No fix yet
MEDIUM 5.3
CVE-2026-19011
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.…
No fix yet
HIGH 7.3
CVE-2026-19010
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c…
No fix yet
HIGH 7.3
CVE-2026-19009
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the compo…
No fix yet
MEDIUM 6.3
CVE-2026-19008
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandb…
No fix yet
MEDIUM 5.0
CVE-2026-18915
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allow…
No fix yet