vuln
feed
2026-09-18 · 14649 vulnerabilities
new today
NVD · Ubuntu · Debian · CISA KEV · OSS-Security · OpenStack · Kubernetes · Exploit-DB · Red Hat · GitHub · OSV
Today (live)
🚫 Patch now
⚠ 0-days
📅 New this week
📈 Trending
Stats
🔍 Search
Archive
🛡 How to scan
📊 Grafana
⚡ n8n
🤖 Agents
🔔 Subscribe
▸ RSS
API
{ } JSON
📧 Weekly digest
Dismiss
Clear reviewed
Browse by product
Kubernetes
53
nginx
29
OpenSSL
38
OpenSSH
14
Linux Kernel
1244
Docker
39
OpenStack
14
Redis
19
PostgreSQL
47
Django
18
Flask
3
Spring Framework
10
Grafana
1
HashiCorp Vault
12
Cilium
1
containerd
12
curl
40
Ansible
4
Jenkins
21
GitLab
22
Cisco
85
Arista
40
Microsoft
9288
Windows
2094
VMware
3
Fortinet
2
Citrix
1
F5
60
Browse by weakness
SQL Injection
140
Cross-Site Scripting (XSS)
269
OS Command Injection
125
Path Traversal
157
Out-of-bounds Write
174
Out-of-bounds Read
193
Use After Free
693
Code Injection
87
Deserialization
50
XML External Entity (XXE)
13
Server-Side Request Forgery (SSRF)
121
Cross-Site Request Forgery (CSRF)
68
Integer Overflow
178
NULL Pointer Dereference
137
Privilege Escalation
276
Missing Authentication
142
Improper Input Validation
144
Buffer Overflow
336
Hardcoded Credentials
28
Unrestricted File Upload
37
★ Watchlist keywords:
Add
Show only
Vulnerabilities — last 14 days
Clear
All Severity
Critical
High
Medium
Low
Unknown
All Sources
NVD
Ubuntu
Debian
CISA KEV
OSS-Security
OpenStack
Kubernetes
Exploit-DB
Red Hat
GitHub
OSV
Cisco
Arista
Microsoft
Fortinet
Juniper
Period:
All time
Last 24h
Last 7 days
Last 30 days
Last year
New since yesterday
★ Watchlist
Sort:
Severity
Newest first
Score
EPSS
Showing
0
of
14649
— Press
Esc
to clear
Vulnerabilities
Security News
0
↓ CSV
🔗 Share
🔔 Get notified about critical CVEs
📧 Email digest
🔔 Push (ntfy.sh)
▸ RSS
All options →
✕
Loading vulnerabilities…
No results
Try a different keyword or clear the filters.
×
📧
Weekly Digest
Top CVEs every Monday. No spam, unsubscribe anytime.
Topics — leave blank for everything
Kubernetes
Windows
Linux Kernel
Ubuntu
Debian
OpenStack
Cisco
Fortinet
VMware
macOS
Android
nginx
Subscribe
✓ Subscribed — see you Monday!
Recent Critical & High-Severity CVEs
CVE-2026-85706
: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2
[CRITICAL 10.0]
CVE-2026-81648
: The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check
[CRITICAL 10.0]
CVE-2026-82434
: Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeepe
[CRITICAL 10.0]
CVE-2026-65381
: A validation issue existed in the entitlement verification. This issue was addressed with improved v
[CRITICAL 10.0]
CVE-2026-59971
: MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL datab
[CRITICAL 10.0]
CVE-2026-53710
: MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to
[CRITICAL 10.0]
CVE-2026-71133
: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic
[CRITICAL 10.0]
CVE-2026-83020
: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
[CRITICAL 10.0]
CVE-2026-83021
: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Cont
[CRITICAL 10.0]
CVE-2026-83059
: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID L
[CRITICAL 10.0]
CVE-2026-83099
: Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/
[CRITICAL 10.0]
CVE-2026-87230
: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec
[CRITICAL 10.0]
CVE-2026-70416
: Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerabil
[CRITICAL 10.0]
CVE-2026-20130
: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity
[CRITICAL 10.0]
CVE-2026-20192
: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity
[CRITICAL 10.0]
CVE-2026-76423
: A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remot
[CRITICAL 10.0]
CVE-2026-92808
: A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Ente
[CRITICAL 10.0]
CVE-2026-76460
: A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, re
[CRITICAL 10.0]
CVE-2026-62104
: Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
[CRITICAL 10.0]
CVE-2026-92937
: vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js pr
[CRITICAL 10.0]
CVE-2026-92940
: vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed cod
[CRITICAL 10.0]
CVE-2026-92941
: vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing a
[CRITICAL 10.0]
CVE-2026-92946
: vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled wi
[CRITICAL 10.0]
CVE-2026-92947
: vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host m
[CRITICAL 10.0]
CVE-2026-92955
: vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access
[CRITICAL 10.0]
CVE-2026-92956
: vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sand
[CRITICAL 10.0]
CVE-2026-92960
: vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configura
[CRITICAL 10.0]
CVE-2026-54734
: Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters in
[CRITICAL 10.0]
CVE-2026-69399
: Azure Arc Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-69865
: Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthori
[CRITICAL 10.0]
CVE-2026-70200
: Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a
[CRITICAL 10.0]
CVE-2026-83944
: Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges ov
[CRITICAL 10.0]
CVE-2026-85889
: Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to
[CRITICAL 10.0]
CVE-2026-62874
: Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to e
[CRITICAL 10.0]
CVE-2026-69843
: Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate pri
[CRITICAL 10.0]
CVE-2026-93603
: vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the appl
[CRITICAL 10.0]
CVE-2026-93605
: vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTIN
[CRITICAL 10.0]
CVE-2026-93606
: vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedde
[CRITICAL 10.0]
CVE-2025-15399
: IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2
[CRITICAL 10.0]
CVE-2026-10747
: IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute a
[CRITICAL 10.0]
CVE-2025-55241
: Azure Entra ID Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-54914
: Azure Networking Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-53767
: Azure OpenAI Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-56162
: Azure SQL Database Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-63508
: Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-65667
: Microsoft Teams Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-65770
: Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-65801
: Microsoft Exchange Online Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-65816
: Azure Arc Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-69502
: Azure SQL Database Elevation of Privilege Vulnerability
[CRITICAL 10.0]