Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-64630
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
No fix yet
CRITICAL 9.8
CVE-2026-63456
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…
No fix yet
CRITICAL 9.8
CVE-2026-63455
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…
Mitigation only
CRITICAL 9.5
CVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credenti…
No fix yet
CRITICAL 9.0
CVE-2026-58072
A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.
Mitigation only
HIGH 8.2
CVE-2026-58071
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator dur…
No fix yet
HIGH 8.7
CVE-2026-58067
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
No fix yet
HIGH 7.5
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resu…
No fix yet
MEDIUM 6.7
CVE-2026-48121
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and belo…
Patch available
HIGH 8.8
CVE-2026-18787
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.…
No fix yet
MEDIUM 5.3
CVE-2026-18785
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the…
No fix yet
MEDIUM 5.3
CVE-2026-18784
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_cli…
No fix yet
MEDIUM 6.3
CVE-2026-18775
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/…
No fix yet
MEDIUM 6.3
CVE-2026-18774
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of …
No fix yet
HIGH 8.8
CVE-2026-15307
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango spatial lookups optimistically parse the right-hand-side value as…
Django
5.2.17 / 6.0.8+
MEDIUM 6.1
CVE-2026-15920
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.contrib.admin.utils.display_for_field()` renders `URLField` values …
Django
5.2.17 / 6.0.8+
MEDIUM 5.3
CVE-2026-15830
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potentia…
Django
5.2.17 / 6.0.8+
MEDIUM 5.3
CVE-2026-15337
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential d…
Django
5.2.17 / 6.0.8+
HIGH 7.5
CVE-2026-15314
Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insu…
Tapo P110 Firmware
1.1.4+
CRITICAL 9.8
CVE-2025-29296
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100…
No fix yet
CRITICAL 9.4
CVE-2026-69254
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-prov…
Patch available
CRITICAL 9.0
CVE-2026-69253
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool compo…
Patch available
HIGH 7.2
CVE-2026-69252
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only b…
Patch available
CRITICAL 9.1
CVE-2026-69110
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files wit…
Patch available
HIGH 8.8
CVE-2026-69100
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes u…
Patch available
CRITICAL 9.8
CVE-2026-69098
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to …
Mitigation only
HIGH 7.6
CVE-2026-25292
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Sm6225p Firmware
Patch available
CRITICAL 9.6
CVE-2026-25289
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Sm7550p Firmware
No fix yet
HIGH 7.8
CVE-2026-24083
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Qam8295p Firmware
Patch available
HIGH 7.4
CVE-2026-25288
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Orne Firmware
No fix yet