Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-14981
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14976
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-14974
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.3
CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Aspera
after 1.0.19
HIGH 7.2
CVE-2026-14959
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Aspera Faspex
5.0.16+
HIGH 7.2
CVE-2026-14958
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Aspera Faspex
5.0.16+
HIGH 7.3
CVE-2026-14893
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable t…
No fix yet
HIGH 7.5
CVE-2026-14528
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 6.1
CVE-2026-14515
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14512
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14446
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Websphere Application Server
8.5.5.30 / 9.0.5.28+
HIGH 7.5
CVE-2026-13463
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
Cloud Pak System
No fix yet
HIGH 7.1
CVE-2026-13442
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence…
Langflow
1.10.2+
MEDIUM 5.4
CVE-2026-57511
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by in…
Patch available
HIGH 8.8
CVE-2026-57510
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user…
Patch available
HIGH 7.5
CVE-2026-55555
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the …
Dompdf
3.16+
HIGH 7.5
CVE-2026-55554
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() pref…
Dompdf
3.1.6+
HIGH 8.1
CVE-2026-48060
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in con…
Mitigation only
HIGH 8.8
CVE-2026-16347
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system…
No fix yet
MEDIUM 6.5
CVE-2026-16192
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feat…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-16184
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 5.9
CVE-2026-16107
IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…
No fix yet
MEDIUM 6.3
CVE-2026-11391
Tanium addressed a SQL injection vulnerability in Patch.
No fix yet
MEDIUM 6.5
CVE-2026-7362
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…
Sterling B2b Integrator
after 6.2.2.0_1
HIGH 8.1
CVE-2026-7769
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…
Sterling B2b Integrator
after 6.2.2.0_1
HIGH 7.5
CVE-2026-66745
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at…
No fix yet
HIGH 7.5
CVE-2026-59932
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …
Patch available
HIGH 7.7
CVE-2026-50738
A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has be…
No fix yet
CRITICAL 9.0
CVE-2026-50737
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the s…
No fix yet
CRITICAL 9.0
CVE-2026-50736
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads…
No fix yet