Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-64793
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could …
No fix yet
HIGH 7.5
CVE-2026-64792
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing cou…
No fix yet
HIGH 8.8
CVE-2026-64791
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and i…
No fix yet
HIGH 8.8
CVE-2026-63685
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistent…
No fix yet
HIGH 8.8
CVE-2026-63684
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Lab…
No fix yet
HIGH 7.5
CVE-2026-63683
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable …
No fix yet
HIGH 8.8
CVE-2026-63280
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration…
No fix yet
HIGH 8.0
CVE-2026-63265
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged …
No fix yet
HIGH 7.5
CVE-2026-13089
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify.
When …
Patch available
HIGH 7.8
CVE-2025-60835
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
Patch available
HIGH 8.8
CVE-2025-50330
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipge…
No fix yet
CRITICAL 9.8
CVE-2025-50329
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the po…
Patch available
HIGH 8.8
CVE-2025-50327
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of th…
No fix yet
MEDIUM 5.4
CVE-2025-50325
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protec…
No fix yet
HIGH 8.8
CVE-2025-50324
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
No fix yet
HIGH 8.8
CVE-2025-44090
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
No fix yet
HIGH 8.8
CVE-2025-44089
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
No fix yet
MEDIUM 6.5
CVE-2026-9737
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may…
No fix yet
HIGH 7.4
CVE-2026-64829
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to re…
Patch available
HIGH 7.5
CVE-2026-14899
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowi…
Thunderbird
140.13.0+
HIGH 7.8
CVE-2026-14881
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In …
No fix yet
HIGH 7.7
CVE-2026-13078
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…
MongoDB
7.0.39 / 8.0.28+
HIGH 7.1
CVE-2026-13077
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13076
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ…
MongoDB
8.3.7+
MEDIUM 6.5
CVE-2026-13075
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio…
MongoDB
8.2.12 / 8.3.7+
MEDIUM 5.3
CVE-2026-13074
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await…
MongoDB
7.0.39 / 8.0.28+
HIGH 8.1
CVE-2026-13072
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13071
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 5.3
CVE-2026-13070
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during t…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13069
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption f…
MongoDB
7.0.39 / 8.0.28+