Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2026-49221
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset…
Patch available
MEDIUM 5.3
CVE-2026-46482
### Impact
The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challe…
Patch available
MEDIUM 5.3
CVE-2026-45734
MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remot…
Patch available
MEDIUM 5.3
CVE-2026-45125
MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail h…
Patch available
MEDIUM 5.4
CVE-2026-45120
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w…
Patch available
CRITICAL 9.3
CVE-2026-45118
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in…
No fix yet
CRITICAL 9.8
CVE-2026-45117
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura…
Patch available
HIGH 8.7
CVE-2026-45116
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field …
Patch available
HIGH 8.7
CVE-2026-45115
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to…
No fix yet
HIGH 8.8
CVE-2026-19501
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form…
Fix unknown
HIGH 7.5
CVE-2026-19500
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or sub…
No fix yet
MEDIUM 6.0
CVE-2026-15806
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d…
Patch available
CRITICAL 9.6
CVE-2026-12564
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r…
No fix yet
HIGH 8.5
CVE-2026-75898
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The …
Patch available
MEDIUM 6.9
CVE-2026-75872
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send …
Patch available
CRITICAL 10.0
CVE-2026-75784
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …
No fix yet
MEDIUM 6.3
CVE-2026-75032
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile …
No fix yet
CRITICAL 9.3
CVE-2026-74015
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
No fix yet
HIGH 8.8
CVE-2026-74012
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection.
This issue affects TaxoPress: from n/a through 3.51.0.
No fix yet
MEDIUM 5.3
CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
No fix yet
MEDIUM 5.3
CVE-2026-74008
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
No fix yet
MEDIUM 5.3
CVE-2026-74007
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
No fix yet
MEDIUM 5.4
CVE-2026-74004
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
No fix yet
HIGH 7.5
CVE-2026-73997
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73996
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
No fix yet
MEDIUM 5.4
CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
No fix yet
HIGH 7.5
CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
No fix yet
HIGH 8.1
CVE-2026-73400
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73399
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
No fix yet