Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-5491
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
HIGH 8.8
CVE-2026-5490
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…
No fix yet
MEDIUM 5.3
CVE-2026-5489
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
HIGH 7.5
CVE-2026-5487
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
HIGH 7.5
CVE-2026-5057
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv…
No fix yet
HIGH 7.8
CVE-2026-5056
GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…
No fix yet
MEDIUM 5.4
CVE-2026-18266
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe…
No fix yet
HIGH 8.8
CVE-2026-18022
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary …
Pgvector
0.8.6+
MEDIUM 5.4
CVE-2026-16553
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer…
GitLab
19.0.5 / 19.1.3+
HIGH 7.5
CVE-2026-15975
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …
GitLab
19.0.5 / 19.1.3+
HIGH 7.8
CVE-2026-13268
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p…
No fix yet
MEDIUM 5.3
CVE-2026-13113
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer…
GitLab
19.0.5 / 19.1.3+
HIGH 8.4
CVE-2026-12436
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …
GitLab
19.0.5 / 19.1.3+
HIGH 7.2
CVE-2026-12357
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…
No fix yet
CRITICAL 10.0
CVE-2026-67429
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…
Patch available
HIGH 8.5
CVE-2026-67428
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_par…
Patch available
HIGH 8.6
CVE-2026-67427
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} f…
Patch available
CRITICAL 9.3
CVE-2026-67426
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…
Patch available
HIGH 8.6
CVE-2026-67425
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and AN…
Patch available
HIGH 8.5
CVE-2026-67424
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in…
Patch available
HIGH 8.6
CVE-2026-67201
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host…
Patch available
HIGH 7.5
CVE-2026-59898
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSoc…
Netty
4.1.136 / 4.2.16+
HIGH 8.8
CVE-2026-2482
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe…
Websphere Application Server
26.0.0.9+
HIGH 8.6
CVE-2026-16328
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid…
No fix yet
CRITICAL 10.0
CVE-2026-16326
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen…
No fix yet
CRITICAL 9.8
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 6.5
CVE-2026-13346
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when ins…
Pip
26.2+
HIGH 8.7
CVE-2026-12935
The
TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
module that can lead to a stack-based buffer overflow. The issue occ…
No fix yet
HIGH 7.4
CVE-2026-8497
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS,…
Password Manager
2026.2.2.0+
MEDIUM 6.5
CVE-2026-59920
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( St…
Netty
4.1.136 / 4.2.16+