Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-24084
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Sdx57m Firmware
No fix yet
HIGH 7.8
CVE-2026-24080
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Qam8295p Firmware
No fix yet
HIGH 8.1
CVE-2026-24079
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Ar8035 Firmware
No fix yet
MEDIUM 6.5
CVE-2026-24078
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
5g Fixed Wireless Access Platform Firmware
No fix yet
MEDIUM 6.5
CVE-2026-24077
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Aqt1000 Firmware
Patch available
MEDIUM 6.7
CVE-2026-24076
Memory Corruption when processing registry values with incorrect types using a direct query method.
Aqt1000 Firmware
No fix yet
HIGH 7.8
CVE-2026-21366
Memory corruption while processing a packet with a size close to the maximum allowed value.
Lemans Au Lgit Firmware
No fix yet
CRITICAL 9.3
CVE-2026-18801
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values.
An attacker who ca…
No fix yet
MEDIUM 6.3
CVE-2026-18773
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gate…
No fix yet
MEDIUM 6.1
CVE-2026-10032
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent …
No fix yet
CRITICAL 9.0
CVE-2026-69251
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory node…
No fix yet
HIGH 8.5
CVE-2026-69250
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/…
Patch available
HIGH 8.7
CVE-2026-68494
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parse…
Patch available
MEDIUM 6.5
CVE-2026-67618
marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a ma…
Patch available
HIGH 7.5
CVE-2026-67200
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesy…
No fix yet
MEDIUM 6.5
CVE-2026-67199
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a…
No fix yet
HIGH 7.5
CVE-2026-67198
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to…
No fix yet
MEDIUM 5.4
CVE-2026-67196
Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaS…
No fix yet
HIGH 8.8
CVE-2026-67195
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands…
No fix yet
CRITICAL 9.8
CVE-2026-61515
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execut…
No fix yet
CRITICAL 9.8
CVE-2026-61514
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access de…
No fix yet
HIGH 7.3
CVE-2026-18770
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /c…
No fix yet
MEDIUM 6.3
CVE-2026-18766
A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of …
No fix yet
HIGH 8.8
CVE-2026-18650
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.
No fix yet
MEDIUM 6.9
CVE-2026-18401
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default…
Patch available
MEDIUM 6.5
CVE-2026-11368
The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_dat…
Zephyr
4.5.0+
MEDIUM 6.5
CVE-2026-70368
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A re…
No fix yet
MEDIUM 5.4
CVE-2026-70367
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a …
No fix yet
HIGH 8.8
CVE-2026-17070
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects L…
No fix yet
HIGH 8.8
CVE-2026-70373
Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-contro…
No fix yet