Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-10545
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w…
Planning Analytics Local
after 2.1.21
HIGH 7.8
CVE-2026-10535
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Db2
12.1.5+
MEDIUM 5.5
CVE-2025-36374
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v…
No fix yet
MEDIUM 6.1
CVE-2025-0152
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site…
Engineering Requirements Management Doors Web Access
after 9.7.2.11
MEDIUM 6.3
CVE-2024-40683
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…
Operations Analytics Log Analysis
after 1.3.8.4
HIGH 7.5
CVE-2024-25039
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of …
Engineering Requirements Management Doors Web Access
after 9.7.2.11
HIGH 7.5
CVE-2026-9322
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of …
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 6.1
CVE-2026-66414
Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users …
Patch available
MEDIUM 5.4
CVE-2026-54522
MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/bu…
Messagepack
1.8.2+
HIGH 7.5
CVE-2026-62663
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc…
No fix yet
HIGH 8.7
CVE-2026-54722
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts st…
Patch available
CRITICAL 9.8
CVE-2026-51291
sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.
No fix yet
CRITICAL 9.1
CVE-2026-51290
SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi…
No fix yet
CRITICAL 9.1
CVE-2026-13379
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras…
Openvpn
2.7.5+
HIGH 8.1
CVE-2026-13117
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during…
Openvpn
2.6.21 / 2.7.5+
HIGH 8.1
CVE-2026-12996
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv…
Openvpn
2.6.21 / 2.7.5+
HIGH 7.1
CVE-2026-12945
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on …
Langflow
1.10.2+
CRITICAL 9.8
CVE-2026-12940
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C…
Langflow
1.10.2+
HIGH 8.1
CVE-2026-12932
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause…
Openvpn
2.6.21 / 2.7.5+
HIGH 8.4
CVE-2026-11885
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call…
No fix yet
HIGH 7.5
CVE-2026-11771
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to…
Openvpn
2.6.21 / 2.7.5+
MEDIUM 6.2
CVE-2026-67596
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all st…
No fix yet
CRITICAL 9.8
CVE-2026-52680
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …
Kyuubi
1.12.0+
HIGH 8.8
CVE-2026-58222
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When…
Mitigation only
MEDIUM 5.3
CVE-2026-58216
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed…
No fix yet
HIGH 8.5
CVE-2026-57862
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin…
No fix yet
MEDIUM 6.5
CVE-2026-44617
LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins…
Zeppelin
0.12.1+
MEDIUM 6.5
CVE-2026-44616
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al…
Zeppelin
0.12.1+
MEDIUM 6.1
CVE-2026-44613
Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a…
Zeppelin
0.12.1+
CRITICAL 9.8
CVE-2026-4978
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL …
No fix yet