Vulnerability feed
533 CVEs (120 known exploited) from the last 120 days, ranked by priority: exploited in the wild, public exploit code, severity, ransomware use, vendor watchlist and news coverage.
- 115CVE-2026-88772Citrix NetScaler
- 115CVE-2026-88771Citrix NetScaler
- 105CVE-2026-15409SonicWall SMA1000 Appliances
- 100CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- 95CVE-2026-102489Zammad GmbH Zammad
- 95CVE-2026-76460Cisco Identity Services Engine
- 95CVE-2026-83548SonicWall SMA1000 Appliances
- 95CVE-2026-59310Broadcom VMware vCenter
- 95CVE-2026-55040Microsoft SharePoint
- 95CVE-2026-39808Fortinet FortiSandbox
- 95CVE-2026-15410SonicWall SMA1000 Appliances
- 95CVE-2026-45659Microsoft SharePoint Server
- 95CVE-2026-20253Splunk Enterprise
- 90CVE-2026-76504Cisco Catalyst SD-WAN Manager
- 90CVE-2026-65660Microsoft SharePoint
- 90CVE-2026-76461Cisco Secure Email Gateway
- 85CVE-2026-88779Citrix NetScaler
- 85CVE-2026-104286Fortinet FortiMail
- 85CVE-2026-86950Apple Multiple Products
- 85CVE-2026-94127F5 BIG-IP APM
- 85CVE-2025-39964Linux Kernel
- 85CVE-2026-53266Linux Kernel
- 85CVE-2025-39682Linux Kernel
- 85CVE-2026-19490Citrix NetScaler
- 85CVE-2026-53362Linux Kernel
- 85CVE-2022-0995Linux Kernel
- 85CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway
- 85CVE-2019-1068Microsoft SQL Server
- 85CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
- 85CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions
- 85CVE-2026-65400Apple macOS
- 85CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock
- 85CVE-2026-63077JetBrains TeamCity
- 85CVE-2026-20316Cisco Secure Firewall Management Center (FMC)
- 85CVE-2026-50522Microsoft SharePoint
- 85CVE-2026-25089Fortinet FortiSandbox
- 85CVE-2026-46817Oracle E-Business Suite
- 85CVE-2026-56164Microsoft SharePoint Server
- 85CVE-2026-20230Cisco Unified Communications Manager
- 85CVE-2026-20262Cisco Catalyst SD-WAN Manager
- 80CVE-2015-3306ProFTPD ProFTPD
- 80CVE-2026-102490Zammad GmbH Zammad
- 80CVE-2026-58644Microsoft SharePoint
- 75CVE-2026-87902WordPress Core
- 75CVE-2026-71362Adobe Commerce and Magento
- 75CVE-2026-85706GitLab Community Edition and Enterprise Edition
- 75CVE-2026-81963Microsoft Windows
- 75CVE-2026-85880Microsoft Windows
- 75CVE-2026-86218N-able N-central
- 75CVE-2026-48710Kludex Starlette
- 75CVE-2026-82329JFrog Artifactory
- 75CVE-2026-9586Sangoma Switchvox
- 75CVE-2026-81578PaperCut NG/MF
- 75CVE-2026-60004Gitea Gitea
- 75CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)
- 75CVE-2026-64849MLflow MLflow
- 75CVE-2025-62593Ray-Project Ray
- 75CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- 75CVE-2026-72898Metabase Metabase
- 75CVE-2026-8037Progress LoadMaster
- 75CVE-2026-34486Apache Tomcat
- 75CVE-2026-9198IBM Langflow
- 75CVE-2026-18577N-able N-central
- 75CVE-2026-16232Check Point SmartConsole
- 75CVE-2026-63030WordPress Core
- 75CVE-2026-0770Langflow Langflow
- 75CVE-2026-56291Balbooa Forms
- 75CVE-2026-48939iCagenda iCagenda
- 75CVE-2026-48908JoomShaper SP Page Builder
- 75CVE-2026-56290Joomlack Page Builder
- 75CVE-2026-48282Adobe ColdFusion
- 75CVE-2026-48558SimpleHelp SimpleHelp
- 75CVE-2026-34910Ubiquiti UniFi OS
- 75CVE-2026-34908Ubiquiti UniFi OS
- 75CVE-2026-48907Widget Factory Joomla Content Editor
- 70CVE-2015-5477ISC BIND
- 70CVE-2023-22894Strapi Strapi
- 70CVE-2025-25249Fortinet Multiple Products
- 70CVE-2026-87491Google Chromium V8
- 70CVE-2026-83549SonicWall SMA1000 Appliances
- 70CVE-2025-68686Fortinet FortiOS
- 70CVE-2026-56155Microsoft Active Directory Federation Services
- 70CVE-2008-4128Cisco IOS
- 65CVE-2016-3081Apache Struts
- 65CVE-2026-88773citrix netscaler application delivery controller
- 65CVE-2026-67279MikroTik RouterOS
- 65CVE-2026-5430WSO2 Multiple Products
- 65CVE-2026-93616Check Point Multiple Products
- 65CVE-2026-85102Check Point Multiple Products
- 65CVE-2026-86060MikroTik RouterOS
- 65CVE-2026-75650Adobe Commerce and Magento
- 65CVE-2026-85046Google Chromium V8
- 65CVE-2026-59822BerriAI LiteLLM
- 65CVE-2026-49869Kestra Kestra OSS
- 65CVE-2023-49105ownCloud ownCloud
- 65CVE-2026-66384JFrog Artifactory
- 65CVE-2021-23758Ajax.NET Professional Ajax.NET Professional
- 65CVE-2015-3246Red Hat Libuser
- 65CVE-2015-5287Red Hat Automatic Bug Reporting Tool
- 65CVE-2026-72530TrueConf Server
- 65CVE-2026-18556N-able N-central
- 65CVE-2026-60137WordPress Core
- 65CVE-2026-55255Langflow Langflow
- 65CVE-2025-67038Lantronix EDS5000
- 65CVE-2026-54420LiteSpeed cPanel Plugin
- 60CVE-2026-76459As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has co
- 60CVE-2026-42018JFrog Artifactory
- 60CVE-2026-12569PTC Windchill and FlexPLM
- 55CVE-2021-3199ONLYOFFICE Docs
- 55CVE-2026-76454A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager
- 55CVE-2026-62874microsoft azure billing
- 55CVE-2026-85889microsoft azure ai foundry
- 55CVE-2026-85885microsoft 365 copilot
- 55CVE-2026-83944microsoft azure logic apps
- 55CVE-2026-77903microsoft dataverse
- 55CVE-2026-70200microsoft azure logic apps
- 55CVE-2026-70009microsoft azure arc
- 55CVE-2026-69399microsoft azure arc
- 50CVE-2026-106237google chrome
- 50CVE-2026-106195google chrome
- 50CVE-2026-88776citrix netscaler application delivery controller
- 50CVE-2026-93952Arista VeloCloud Orchestrator
- 50CVE-2026-7273Zyxel GS1900 Series Switches
- 50CVE-2026-58704Google Pixel
- 50CVE-2026-87886Acronis Backup
- 50CVE-2026-65381apple macos
- 50CVE-2026-43790apple macos
- 50CVE-2026-84869ConnectWise ScreenConnect
- 50CVE-2026-42016JFrog Artifactory
- 50CVE-2026-67277MikroTik RouterOS
- 50CVE-2026-82078PaperCut NG/MF
- 50CVE-2026-72529TrueConf Server
- 50CVE-2026-16812Arista VeloCloud Orchestrator
- 50CVE-2021-27137DD-WRT DD-WRT
- 50CVE-2023-4346KNX Association KNX Protocol Connection Authorization Option 1
- 50CVE-2026-34909Ubiquiti UniFi OS
- 45CVE-2026-82531Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is nev
- 45CVE-2026-102427ordasoft joomla cck
- 45CVE-2026-76570joomcode jc tables
- 45CVE-2026-102425balbooa forms
- 45CVE-2026-101110ordasoft book library
- 45CVE-2026-81642nlnetlabs unbound
- 40CVE-2026-96765The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cr
- 40CVE-2026-104759The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentic
- 40CVE-2026-76468As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team h
- 40CVE-2026-88097microsoft edge chromium
- 40CVE-2026-78501microsoft 365 copilot chat
- 40CVE-2026-68791microsoft azure machine learning
- 35CVE-2026-108598Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attack
- 35CVE-2026-108551openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an O
- 35CVE-2026-108549cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in pla
- 35CVE-2026-104803The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.2
- 35CVE-2026-104801The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion
- 35CVE-2026-97670The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
- 35CVE-2026-103889The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions
- 35CVE-2026-94589The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable
- 35CVE-2026-107645The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.5
- 35CVE-2026-104732The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including
- 35CVE-2026-108107PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST e
- 35CVE-2026-86405Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. Prest
- 35CVE-2026-85531Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenC
- 35CVE-2026-19491ibm security verify access
- 35CVE-2026-16823ibm security verify access
- 35CVE-2026-16916ibm security verify access
- 35CVE-2026-107779Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability i
- 35CVE-2026-107780Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in
- 35CVE-2026-104075TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerabi
- 35CVE-2026-107699ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system c
- 35CVE-2026-106221google chrome
- 35CVE-2026-106198google chrome
- 35CVE-2026-106199google chrome
- 35CVE-2026-106196google chrome
- 35CVE-2026-106188google chrome
- 35CVE-2026-88778citrix netscaler application delivery controller
- 35CVE-2026-88775citrix netscaler application delivery controller
- 35CVE-2026-88777citrix netscaler application delivery controller
- 35CVE-2026-88774citrix netscaler application delivery controller
- 35CVE-2026-98163linux linux kernel
- 35CVE-2026-98136linux linux kernel
- 35CVE-2026-77246mcp-atlassian mcp atlassian
- 35CVE-2026-77271mcp-atlassian mcp atlassian
- 35CVE-2026-77274mcp-atlassian mcp atlassian
- 35CVE-2026-77260mcp-atlassian mcp atlassian
- 35CVE-2026-77261mcp-atlassian mcp atlassian
- 35CVE-2026-91732google chrome
- 35CVE-2026-91719google chrome
- 35CVE-2026-87197oracle hyperion financial management
- 35CVE-2026-84580apple macos
- 35CVE-2026-84584apple macos
- 35CVE-2026-84565apple macos
- 35CVE-2026-84566apple ipados
- 35CVE-2026-84549apple macos
- 35CVE-2026-84544apple macos
- 35CVE-2026-84548apple macos
- 35CVE-2026-65378apple macos
- 35CVE-2026-65342apple macos
- 35CVE-2026-43815apple macos
- 35CVE-2026-43789apple macos
- 35CVE-2026-43697apple macos
- 35CVE-2026-70341microsoft edge
- 30CVE-2026-54472dell container storage modules
- 30CVE-2026-86131watchguard fireware
- 30CVE-2026-102828simple-git project simple-git
- 30CVE-2026-101077A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp
- 30CVE-2026-101072A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.c
- 30CVE-2026-100390Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded
- 30CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobi
- 30CVE-2026-93834A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker
- 30CVE-2026-81549ibm datastage on cloud pak for data
- 30CVE-2026-6730ibm concert
- 30CVE-2026-86930claris filemaker server
- 30CVE-2026-96755orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts
- 30CVE-2026-95848moquette moquette
- 30CVE-2026-17645ibm financial transaction manager
- 30CVE-2026-77987github enterprise server
- 30CVE-2026-28324SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability
- 30CVE-2026-89276adobe campaign
- 30CVE-2026-83660adobe campaign
- 30CVE-2026-82009adobe campaign
- 30CVE-2026-82443adobe campaign
- 30CVE-2026-95654Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization de
- 30CVE-2026-80442ibm guardium data protection
- 30CVE-2026-93659Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a
- 30CVE-2026-92913AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number genera
- 30CVE-2026-91104hp linux imaging and printing
- 30CVE-2026-91106hp linux imaging and printing
- 30CVE-2026-91097hp linux imaging and printing
- 30CVE-2026-70416dell objectscale
- 30CVE-2026-18110concretecms concrete cms
- 30CVE-2026-91988atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowin
- 30CVE-2026-91940crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt
- 30CVE-2026-16338ibm datastage on cloud pak for data
- 30CVE-2026-82617apache opennlp
- 30CVE-2026-89043passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and
- 30CVE-2026-81468dell thinos
- 30CVE-2026-81048dell thinos
- 30CVE-2026-88007traefik traefik
- 30CVE-2026-88008traefik traefik
- 30CVE-2026-9163Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics Gi
- 20CVE-2026-108657JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that
- 20CVE-2026-108628JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepa
- 20CVE-2026-108623JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that
- 20CVE-2026-108550SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeControll
- 20CVE-2026-108553OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote
- 20CVE-2026-108546Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote at
- 20CVE-2026-108161FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauth
- 20CVE-2026-91136The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the
- 20CVE-2026-107657The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-
- 20CVE-2026-96662The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to g
- 20CVE-2026-96278The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session Histor
- 20CVE-2026-93746The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab
- 20CVE-2026-100178The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_lo
- 20CVE-2026-101920The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to S
- 20CVE-2026-100147The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
- 20CVE-2026-94538The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.
- 20CVE-2026-95684The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachm
- 20CVE-2026-96558The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cros
- 20CVE-2026-96572The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Com
- 20CVE-2026-96840The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_nam
- 20CVE-2026-12626The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection
- 20CVE-2026-107742The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Store
- 20CVE-2026-100196The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scri
- 20CVE-2026-100161The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'w
- 20CVE-2026-96667The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site
- 20CVE-2026-96682The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via <presto-play
- 20CVE-2026-92975The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation i
- 20CVE-2026-93775The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in
- 20CVE-2026-77183The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via accoun
- 20CVE-2026-83526The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7
- 20CVE-2026-14335The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored
- 20CVE-2026-104766The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to P
- 20CVE-2026-104899The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to
- 20CVE-2026-104723The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injecti
- 20CVE-2026-104725The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation i
- 20CVE-2026-89301The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to ins
- 20CVE-2026-104021The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.
- 20CVE-2026-104797The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass v
- 20CVE-2026-108159AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that
- 20CVE-2026-108113ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handl
- 20CVE-2026-104082SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-
- 20CVE-2026-108106Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaus
- 20CVE-2026-108108PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Passwor
- 20CVE-2026-108101HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that al
- 20CVE-2026-81932IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker coul
- 20CVE-2026-19493ibm security verify access
- 20CVE-2026-107782System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows l
- 20CVE-2026-84275ibm guardium data protection
- 20CVE-2026-82344ibm guardium data protection
- 20CVE-2026-84250ibm guardium data protection
- 20CVE-2026-82334ibm guardium data protection
- 20CVE-2026-82335ibm guardium data protection
- 20CVE-2026-84276ibm guardium data protection
- 20CVE-2026-107701dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype b
- 20CVE-2026-91844Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd
- 20CVE-2026-106121vmware rabbitmq java client
- 20CVE-2026-106122vmware rabbitmq java client
- 20CVE-2026-77265mcp-atlassian mcp atlassian
- 15CVE-2026-46569tuxera ntfs-3g
- 15CVE-2026-42616tuxera ntfs-3g
- 15CVE-2026-93675langflow langflow
- 15CVE-2026-93449langflow langflow
- 15CVE-2026-93443langflow langflow
- 15CVE-2026-93445langflow langflow
- 15CVE-2026-106509linuxfoundation backstage plugin-techdocs-node
- 15CVE-2026-106505linuxfoundation backstage plugin-techdocs-node
- 15CVE-2026-96890github enterprise server
- 15CVE-2026-106218jetbrains teamcity
- 15CVE-2026-105841lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows re
- 15CVE-2026-105744docling docling
- 15CVE-2026-104714apache struts
- 15CVE-2026-85215Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software S
- 15CVE-2026-93875The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in
- 15CVE-2026-102997pypdf project pypdf
- 15CVE-2026-102998pypdf project pypdf
- 15CVE-2026-102999pypdf project pypdf
- 15CVE-2026-103000pypdf project pypdf
- 15CVE-2026-102995pypdf project pypdf
- 15CVE-2026-102996pypdf project pypdf
- 15CVE-2026-102994pypdf project pypdf
- 15CVE-2026-102993pypdf project pypdf
- 15CVE-2026-101885ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installa
- 15CVE-2026-101884OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to
- 15CVE-2026-101880OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval
- 15CVE-2026-103474yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticate
- 15CVE-2026-100277jetbrains youtrack
- 15CVE-2026-100273jetbrains youtrack
- 15CVE-2026-100262jetbrains youtrack
- 15CVE-2026-100255jetbrains teamcity
- 15CVE-2026-86134watchguard fireware
- 15CVE-2026-103109pexip pexip infinity
- 15CVE-2026-103101pexip pexip infinity
- 15CVE-2026-86133watchguard fireware
- 15CVE-2026-86136watchguard fireware
- 15CVE-2026-90441watchguard fireware
- 15CVE-2026-18145watchguard fireware
- 15CVE-2026-86104watchguard fireware
- 15CVE-2026-86128watchguard fireware
- 15CVE-2026-86132watchguard fireware
- 15CVE-2026-13046watchguard fireware
- 15CVE-2026-102827simple-git project simple-git
- 15CVE-2026-84440ibm guardium data protection
- 15CVE-2026-102811Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmi
- 15CVE-2026-102677electronjs electron
- 15CVE-2026-92222joomla joomla\!
- 15CVE-2026-92227joomla joomla\!
- 15CVE-2026-102424balbooa forms
- 15CVE-2026-101127balbooa forms
- 15CVE-2026-102566CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload
- 15CVE-2026-95387wireshark wireshark
- 15CVE-2026-102266pyjwt project pyjwt
- 15CVE-2026-102267pyjwt project pyjwt
- 15CVE-2026-101081A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp o
- 15CVE-2026-101038A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAt
- 15CVE-2026-93302wolfssl wolfssl
- 15CVE-2026-100846project-monai monai
- 15CVE-2026-100842project-monai monai
- 15CVE-2026-100844project-monai monai
- 15CVE-2026-100833Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe
- 15CVE-2026-100652vllm vllm
- 15CVE-2026-67410broadcom rabbitmq server
- 15CVE-2026-62368snipeitapp snipe-it
- 15CVE-2026-63493snipeitapp snipe-it
- 15CVE-2026-81552ibm datastage on cloud pak for data
- 15CVE-2026-82093ibm datastage on cloud pak for data
- 15CVE-2026-82094ibm datastage on cloud pak for data
- 15CVE-2026-81539ibm datastage on cloud pak for data
- 15CVE-2026-81545ibm datastage on cloud pak for data
- 15CVE-2026-77874IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.
- 15CVE-2026-95843moquette moquette
- 15CVE-2026-95844moquette moquette
- 15CVE-2026-95845moquette moquette
- 15CVE-2026-95846moquette moquette
- 15CVE-2026-95847moquette moquette
- 15CVE-2026-95842moquette moquette
- 15CVE-2026-95676watchguard authentication gateway
- 15CVE-2026-91812foxit pdf editor
- 15CVE-2026-91813foxit pdf editor
- 15CVE-2026-91803foxit pdf editor
- 15CVE-2026-18134ibm financial transaction manager
- 15CVE-2026-18152ibm financial transaction manager
- 15CVE-2026-18154ibm financial transaction manager
- 15CVE-2026-18066ibm financial transaction manager
- 15CVE-2026-18074ibm financial transaction manager
- 15CVE-2026-18095ibm financial transaction manager
- 15CVE-2026-18123ibm financial transaction manager
- 15CVE-2026-17643ibm financial transaction manager
- 15CVE-2026-17644ibm financial transaction manager
- 15CVE-2026-17647ibm financial transaction manager
- 15CVE-2026-63104Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace me
- 15CVE-2026-65130nvidia infra controller
- 15CVE-2026-65118nvidia infra controller
- 15CVE-2026-65121nvidia infra controller
- 15CVE-2026-65114nvidia infra controller
- 15CVE-2026-25255qualcomm package manager
- 15CVE-2026-94501jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent
- 15CVE-2026-94412jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen
- 15CVE-2026-94056exim exim
- 15CVE-2026-57228oisf suricata
- 15CVE-2026-81626ibm guardium data protection
- 15CVE-2017-20284Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthen
- 15CVE-2026-10853ibm mq
- 15CVE-2026-10027ibm mq
- 15CVE-2026-81627A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem
- 15CVE-2026-93014RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing
- 15CVE-2026-26950dell smartfabric manager
- 15CVE-2026-92918admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events
- 15CVE-2026-81440dell openmanage server administrator
- 15CVE-2026-81475dell openmanage server administrator
- 15CVE-2026-81476dell openmanage server administrator
- 15CVE-2026-81478dell openmanage server administrator
- 15CVE-2026-66269dell openmanage server administrator
- 15CVE-2026-24075qualcomm wsa8845h firmware
- 15CVE-2026-25278qualcomm lemans au lgit firmware
- 15CVE-2026-87976apache nifi
- 15CVE-2026-91102hp linux imaging and printing
- 15CVE-2026-91105hp linux imaging and printing
- 15CVE-2026-91098hp linux imaging and printing
- 15CVE-2026-92604Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows d
- 15CVE-2026-92719Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing at
- 15CVE-2026-85385concretecms concrete cms
- 15CVE-2026-71180dell update package framework
- 15CVE-2026-71179dell update package framework
- 15CVE-2025-43936dell objectscale
- 15CVE-2026-92466zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.
- 15CVE-2026-92126jenkins script security
- 15CVE-2026-82717nlnetlabs unbound
- 15CVE-2026-81236dell wyse management suite
- 15CVE-2026-81238dell wyse management suite
- 15CVE-2026-81239dell wyse management suite
- 15CVE-2026-81240dell wyse management suite
- 15CVE-2026-81895concretecms concrete cms
- 15CVE-2026-91973Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiti
- 15CVE-2026-91955freerdp freerdp
- 15CVE-2026-91934Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite datab
- 15CVE-2026-91929Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resour
- 15CVE-2026-90650The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eve
- 15CVE-2026-89025Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to mi
- 15CVE-2026-81901concretecms concrete cms
- 15CVE-2026-81902concretecms concrete cms
- 15CVE-2026-18119concretecms concrete cms
- 15CVE-2026-16335ibm datastage on cloud pak for data
- 15CVE-2026-16466ibm datastage on cloud pak for data
- 15CVE-2026-82035PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_o
- 15CVE-2026-8303Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software
- 15CVE-2026-89161pcre pcre2
- 15CVE-2026-81551ibm datastage on cloud pak for data
- 15CVE-2026-88056angular angular
- 15CVE-2026-88032mongodb java driver
- 15CVE-2026-88051tesseract-ocr tesseract ocr
- 15CVE-2026-88053tesseract-ocr tesseract ocr
- 15CVE-2026-88027mongodb laravel mongodb
- 15CVE-2026-88047tesseract-ocr tesseract ocr
- 15CVE-2026-88048tesseract-ocr tesseract ocr
- 15CVE-2026-88937knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allo
- 15CVE-2026-88009traefik traefik
- 15CVE-2026-88004traefik traefik
- 15CVE-2026-9166Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab L
- 5CVE-2026-108548AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that
- 5CVE-2026-108156LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC h
- 5CVE-2026-78388ibm security verify access
- 5CVE-2026-19498ibm security verify access
- 5CVE-2026-12109ibm security verify access
- 5CVE-2026-11888ibm security verify access
- 5CVE-2026-11930ibm security verify access
- 0CVE-2026-104048fedoraproject sssd
- 0CVE-2026-106219jetbrains teamcity
- 0CVE-2026-105750docling docling
- 0CVE-2026-105745docling docling
- 0CVE-2026-104637A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61
- 0CVE-2026-103678tnef project tnef
- 0CVE-2026-103241vllm vllm
- 0CVE-2026-103229A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c.
- 0CVE-2026-100276jetbrains youtrack
- 0CVE-2026-102578moodle moodle
- 0CVE-2026-86105watchguard fireware
- 0CVE-2026-90906joomla joomla\!
- 0CVE-2026-96423wireshark wireshark
- 0CVE-2026-96419wireshark wireshark
- 0CVE-2026-102274pyjwt project pyjwt
- 0CVE-2026-102275pyjwt project pyjwt
- 0CVE-2026-101917pyjwt project pyjwt
- 0CVE-2026-101918pyjwt project pyjwt
- 0CVE-2026-101066A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packag
- 0CVE-2026-89134wolfssl wolfssl
- 0CVE-2026-94418wolfssl wolfssl
- 0CVE-2026-100647vllm vllm
- 0CVE-2026-97883A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db
- 0CVE-2026-97885A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affecte
- 0CVE-2026-97871A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of
- 0CVE-2026-67411broadcom rabbitmq server
- 0CVE-2026-67412broadcom rabbitmq server
- 0CVE-2026-97865A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of
- 0CVE-2026-18153ibm financial transaction manager
- 0CVE-2026-18114ibm financial transaction manager
- 0CVE-2026-83964adobe connect
- 0CVE-2026-95656A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_wat
- 0CVE-2026-65129nvidia infra controller
- 0CVE-2026-65117nvidia infra controller
- 0CVE-2026-65124nvidia infra controller
- 0CVE-2026-65125nvidia infra controller
- 0CVE-2026-65126nvidia infra controller
- 0CVE-2026-71855oisf suricata
- 0CVE-2026-63448oisf suricata
- 0CVE-2026-81623ibm guardium data protection
- 0CVE-2026-93604vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow
- 0CVE-2026-81438dell openmanage server administrator
- 0CVE-2026-25261qualcomm cologne firmware
- 0CVE-2026-86089apache nifi
- 0CVE-2026-91103hp linux imaging and printing
- 0CVE-2026-91099hp linux imaging and printing
- 0CVE-2026-91100hp linux imaging and printing
- 0CVE-2026-91101hp linux imaging and printing
- 0CVE-2026-92406A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown f
- 0CVE-2026-85387concretecms concrete cms
- 0CVE-2026-86358dell update package framework
- 0CVE-2026-80225nlnetlabs unbound
- 0CVE-2026-85501nlnetlabs unbound
- 0CVE-2026-18424concretecms concrete cms
- 0CVE-2026-18423concretecms concrete cms
- 0CVE-2026-90789A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown funct
- 0CVE-2026-12985mattermost mattermost server
- 0CVE-2026-90554vllm vllm
- 0CVE-2026-90535flowiseai flowise
- 0CVE-2026-81907concretecms concrete cms
- 0CVE-2026-89157pcre pcre2
- 0CVE-2026-78135strongswan strongswan
- 0CVE-2026-9176ibm websphere application server
- 0CVE-2026-9327ibm websphere application server
- 0CVE-2026-45751oisf suricata
- 0CVE-2026-9336ibm websphere application server
- 0CVE-2026-88033mongodb java driver
- 0CVE-2026-88011traefik traefik
- 0CVE-2026-88879traefik traefik