Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2026-7441
The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive`…
No fix yet
HIGH 7.5
CVE-2026-71215
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, reso…
No fix yet
CRITICAL 9.8
CVE-2026-71214
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS…
No fix yet
CRITICAL 9.1
CVE-2026-71213
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when capt…
No fix yet
HIGH 7.1
CVE-2026-71211
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no …
No fix yet
MEDIUM 5.3
CVE-2026-71210
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-ra…
No fix yet
HIGH 7.5
CVE-2026-71209
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requ…
No fix yet
MEDIUM 6.5
CVE-2026-71208
KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's conne…
No fix yet
CRITICAL 9.8
CVE-2026-71207
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly…
No fix yet
HIGH 8.3
CVE-2026-71206
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodi…
No fix yet
MEDIUM 6.5
CVE-2026-71205
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting,…
No fix yet
MEDIUM 6.2
CVE-2026-71204
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application setti…
No fix yet
MEDIUM 5.3
CVE-2026-71203
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec res…
No fix yet
HIGH 7.5
CVE-2026-71202
The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y pa…
No fix yet
HIGH 7.5
CVE-2026-70378
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -…
No fix yet
HIGH 7.5
CVE-2026-70377
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-boun…
No fix yet
CRITICAL 9.6
CVE-2026-70376
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.ph…
No fix yet
MEDIUM 6.4
CVE-2026-6972
The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in…
No fix yet
HIGH 7.5
CVE-2026-6639
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin…
No fix yet
HIGH 8.2
CVE-2026-6627
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment…
No fix yet
HIGH 8.8
CVE-2026-6147
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functi…
No fix yet
HIGH 7.3
CVE-2026-6079
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd…
No fix yet
HIGH 7.2
CVE-2026-6020
The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all vers…
No fix yet
HIGH 7.8
CVE-2026-64581
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
xfrm_user_policy() cle…
No fix yet
HIGH 7.8
CVE-2026-64580
In the Linux kernel, the following vulnerability has been resolved:
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
On…
No fix yet
HIGH 8.2
CVE-2026-64578
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd …
No fix yet
HIGH 7.5
CVE-2026-64577
In the Linux kernel, the following vulnerability has been resolved:
gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
gtp1u_send_echo_res…
No fix yet
HIGH 7.1
CVE-2026-64576
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate()
nh_res_bucket_migrate() p…
No fix yet
HIGH 7.8
CVE-2026-64575
In the Linux kernel, the following vulnerability has been resolved:
bpf: tcp: fix double sock release on batch realloc
bpf_iter_tcp_batch() release…
No fix yet
HIGH 7.8
CVE-2026-64574
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: tear down new links on vif update error path
When ieee80211_vif…
No fix yet