Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.6
CVE-2026-65835
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…
No fix yet
MEDIUM 6.8
CVE-2026-65834
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex a…
No fix yet
CRITICAL 9.9
CVE-2026-12946
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…
Langflow
1.10.1+
HIGH 8.5
CVE-2026-11536
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Websphere Application Server
8.5.5.29 / 9.0.5.28+
MEDIUM 6.1
CVE-2025-51684
CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessa…
No fix yet
HIGH 8.8
CVE-2026-66416
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf …
Patch available
HIGH 8.5
CVE-2026-66415
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal res…
Patch available
CRITICAL 9.5
CVE-2026-66066
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di…
Patch available
MEDIUM 5.3
CVE-2026-64870
MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied downloa…
Patch available
HIGH 7.5
CVE-2026-61536
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered…
No fix yet
MEDIUM 6.9
CVE-2026-59881
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames…
Patch available
CRITICAL 9.8
CVE-2026-51272
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. …
No fix yet
CRITICAL 9.3
CVE-2026-48499
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…
Patch available
HIGH 8.8
CVE-2026-18245
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar…
Amplify Codegen Ui
2.20.6+
HIGH 7.5
CVE-2026-18140
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes fr…
Aws Smithy Json
0.62.7+
HIGH 7.5
CVE-2026-15978
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote at…
Sglang
after 0.5.15
HIGH 7.5
CVE-2026-15977
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the…
Sglang
after 0.5.15
CRITICAL 9.8
CVE-2026-15976
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…
Sglang
after 0.5.15
MEDIUM 6.5
CVE-2026-15974
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access …
Sglang
after 0.5.15
CRITICAL 9.8
CVE-2026-15971
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…
Sglang
after 0.5.15
CRITICAL 9.8
CVE-2026-15969
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…
Sglang
after 0.5.15
HIGH 8.1
CVE-2026-13444
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matchin…
Langflow
1.10.2+
CRITICAL 9.9
CVE-2026-13435
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Langflow
1.10.2+
CRITICAL 9.8
CVE-2026-12943
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…
Hardware Management Console
10.3.1064.1 / 11.1.1112.1+
HIGH 7.5
CVE-2026-12942
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted…
Langflow
1.10.2+
HIGH 7.5
CVE-2026-12733
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Datapower Gateway
10.5.0.22 / 10.6.0.10+
CRITICAL 9.8
CVE-2026-12118
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…
Webmethods Integration
No fix yet
MEDIUM 5.3
CVE-2026-11904
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…
Verify Identity Access
after 11.0.2
MEDIUM 6.5
CVE-2026-10700
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access …
Langflow
1.9.0+
MEDIUM 5.5
CVE-2026-10695
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Db2
12.1.5+