Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-71248
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f…
Patch available
MEDIUM 6.5
CVE-2026-71247
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b…
No fix yet
HIGH 7.1
CVE-2026-71245
Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with Inp…
No fix yet
MEDIUM 6.5
CVE-2026-71244
Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac…
No fix yet
HIGH 8.8
CVE-2026-71243
The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =…
No fix yet
HIGH 8.3
CVE-2026-71242
Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol…
No fix yet
HIGH 7.5
CVE-2026-71241
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required dec…
No fix yet
HIGH 8.1
CVE-2026-71239
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, …
No fix yet
CRITICAL 9.1
CVE-2026-71238
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…
No fix yet
CRITICAL 9.8
CVE-2026-71237
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i…
No fix yet
HIGH 8.7
CVE-2026-71236
Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri…
No fix yet
HIGH 8.8
CVE-2026-71235
Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T…
No fix yet
HIGH 7.5
CVE-2026-71234
Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a…
No fix yet
HIGH 8.7
CVE-2026-71233
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (r…
No fix yet
HIGH 7.2
CVE-2026-71232
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex…
Patch available
CRITICAL 9.8
CVE-2026-71231
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b…
No fix yet
CRITICAL 9.8
CVE-2026-66747
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o…
No fix yet
HIGH 8.8
CVE-2026-60009
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…
Theia
1.74.0+
MEDIUM 6.5
CVE-2026-14574
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va…
Theia
1.74.0+
MEDIUM 5.5
CVE-2026-14304
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…
Accessibility Tools Framework
3.2.0+
HIGH 7.5
CVE-2026-12609
In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e…
Theia
1.74.0+
CRITICAL 9.1
CVE-2026-44945
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w…
Patch available
HIGH 7.3
CVE-2026-25703
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing …
No fix yet
MEDIUM 6.9
CVE-2026-0931
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process…
No fix yet
CRITICAL 9.0
CVE-2026-10090
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet…
No fix yet
CRITICAL 9.1
CVE-2026-10059
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp…
No fix yet
MEDIUM 6.5
CVE-2026-7726
The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::tem…
No fix yet
HIGH 7.2
CVE-2026-7693
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient san…
No fix yet
HIGH 8.1
CVE-2026-7520
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `si…
No fix yet
HIGH 8.1
CVE-2026-7444
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is du…
No fix yet