CVE-2026-44210
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual...
10 CVE-2026-47668
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner...
8.7 CVE-2026-47743
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire...
9.9 CVE-2026-47752
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2...
6.5 CVE-2026-47755
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers....
5.3 CVE-2026-47769
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP...
4.2 CVE-2026-65699
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that...
9.8 CVE-2026-65700
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that...
9.1 CVE-2026-65701
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability...
8.6 CVE-2026-65702
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence...
CVE-2026-65762
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper...
CVE-2026-65763
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation...
7.1 CVE-2026-65918
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability...
7.5 CVE-2026-65919
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView...
4.3 CVE-2026-65920
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files...
10 CVE-2026-6516
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote...
CVE-2026-15687
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be...
7.5 CVE-2026-16756
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default...
8.2 CVE-2026-63765
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller...
6.6 CVE-2026-65010
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract()...
5.3 CVE-2026-12353
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS...