Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2026-75091
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version…
No fix yet
CRITICAL 9.8
CVE-2026-15748
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…
No fix yet
HIGH 7.5
CVE-2026-11801
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…
No fix yet
CRITICAL 9.1
CVE-2026-75094
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid…
No fix yet
HIGH 7.3
CVE-2026-75089
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c…
No fix yet
MEDIUM 6.3
CVE-2026-75088
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi…
No fix yet
MEDIUM 6.3
CVE-2026-75087
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin…
No fix yet
MEDIUM 6.3
CVE-2026-75086
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.…
No fix yet
HIGH 7.3
CVE-2026-75080
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the…
No fix yet
HIGH 7.3
CVE-2026-75079
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_sub…
No fix yet
HIGH 7.8
CVE-2026-67961
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.
No fix yet
CRITICAL 9.8
CVE-2026-67919
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli…
No fix yet
CRITICAL 9.8
CVE-2026-42164
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…
No fix yet
CRITICAL 9.1
CVE-2026-42162
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact…
No fix yet
CRITICAL 9.8
CVE-2026-38165
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t…
Patch available
MEDIUM 6.5
CVE-2026-9859
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the …
Mattermost Server
10.11.22 / 11.7.7+
HIGH 8.3
CVE-2026-9816
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and arc…
Mattermost Server
10.11.22 / 11.7.7+
CRITICAL 9.8
CVE-2026-67960
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C…
No fix yet
CRITICAL 9.6
CVE-2026-71424
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…
Patch available
HIGH 7.1
CVE-2026-69148
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion …
Patch available
MEDIUM 6.5
CVE-2026-69146
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs …
Patch available
HIGH 7.5
CVE-2026-67918
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in…
No fix yet
CRITICAL 9.8
CVE-2026-67868
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This…
No fix yet
CRITICAL 9.8
CVE-2026-67854
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
No fix yet
MEDIUM 6.6
CVE-2026-65349
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app m…
Ipados
26.6.1 / 26.6.2+
MEDIUM 6.5
CVE-2026-65347
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead t…
Ipados
26.6.1 / 26.6.2+
HIGH 8.8
CVE-2026-65346
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing…
Ipados
26.6.1 / 26.6.2+
HIGH 7.5
CVE-2026-65343
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remo…
Ipados
26.6.1 / 26.6.2+
MEDIUM 5.4
CVE-2026-65341
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26…
Safari
18.7.10 / 26.6.1+
MEDIUM 5.0
CVE-2026-65339
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak…
Ipados
26.6.1 / 26.6.2+