vuln
feed
2026-08-15 · 11655 vulnerabilities
new today
NVD · Ubuntu · Debian · CISA KEV · OSS-Security · OpenStack · Kubernetes · Exploit-DB · Red Hat · GitHub · OSV
Today (live)
🚫 Patch now
⚠ 0-days
📅 New this week
📈 Trending
Stats
🔍 Search
Archive
🛡 How to scan
📊 Grafana
⚡ n8n
🤖 Agents
🔔 Subscribe
▸ RSS
API
{ } JSON
📧 Weekly digest
Dismiss
Clear reviewed
Browse by product
Kubernetes
59
nginx
21
OpenSSL
41
OpenSSH
20
Linux Kernel
947
Docker
42
OpenStack
7
Redis
12
PostgreSQL
48
Django
4
Flask
1
Log4j
5
Spring Framework
3
Grafana
2
HashiCorp Vault
11
Traefik
2
Cilium
1
containerd
17
curl
24
Ansible
3
GitLab
14
Cisco
1
Arista
3
Microsoft
8182
Windows
1458
Fortinet
7
Palo Alto
12
Ivanti
3
F5
99
Browse by weakness
SQL Injection
128
Cross-Site Scripting (XSS)
153
OS Command Injection
162
Path Traversal
166
Out-of-bounds Write
119
Out-of-bounds Read
172
Use After Free
653
Code Injection
56
Deserialization
37
XML External Entity (XXE)
8
Server-Side Request Forgery (SSRF)
105
Cross-Site Request Forgery (CSRF)
38
Integer Overflow
205
NULL Pointer Dereference
145
Privilege Escalation
114
Missing Authentication
54
Improper Input Validation
73
Buffer Overflow
392
Hardcoded Credentials
28
Unrestricted File Upload
26
★ Watchlist keywords:
Add
Show only
Vulnerabilities — last 14 days
Clear
All Severity
Critical
High
Medium
Low
Unknown
All Sources
NVD
Ubuntu
Debian
CISA KEV
OSS-Security
OpenStack
Kubernetes
Exploit-DB
Red Hat
GitHub
OSV
Cisco
Arista
Microsoft
Fortinet
Juniper
Period:
All time
Last 24h
Last 7 days
Last 30 days
Last year
New since yesterday
★ Watchlist
Sort:
Severity
Newest first
Score
EPSS
Showing
0
of
11655
— Press
Esc
to clear
Vulnerabilities
Security News
0
↓ CSV
🔗 Share
🔔 Get notified about critical CVEs
📧 Email digest
🔔 Push (ntfy.sh)
▸ RSS
All options →
✕
Loading vulnerabilities…
No results
Try a different keyword or clear the filters.
×
📧
Weekly Digest
Top CVEs every Monday. No spam, unsubscribe anytime.
Topics — leave blank for everything
Kubernetes
Windows
Linux Kernel
Ubuntu
Debian
OpenStack
Cisco
Fortinet
VMware
macOS
Android
nginx
Subscribe
✓ Subscribed — see you Monday!
Recent Critical & High-Severity CVEs
CVE-2026-66915
: Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attac
[CRITICAL 10.0]
CVE-2026-72898
: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password'
[CRITICAL 10.0]
CVE-2026-72899
: Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or da
[CRITICAL 10.0]
CVE-2026-58231
: SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and s
[CRITICAL 10.0]
CVE-2026-58115
: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions <
[CRITICAL 10.0]
CVE-2026-48056
: Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p
[CRITICAL 10.0]
CVE-2026-17061
: A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 20
[CRITICAL 10.0]
CVE-2026-48362
: ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS
[CRITICAL 10.0]
CVE-2026-27302
: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu
[CRITICAL 10.0]
CVE-2026-71398
: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu
[CRITICAL 10.0]
CVE-2026-45618
: LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possi
[CRITICAL 10.0]
CVE-2026-67282
: Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unaut
[CRITICAL 10.0]
CVE-2026-73299
: Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the T
[CRITICAL 10.0]
CVE-2024-27253
: IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass secur
[CRITICAL 10.0]
CVE-2026-15413
: The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it
[CRITICAL 10.0]
CVE-2026-59500
: CWE-287: Improper Authentication
[CRITICAL 10.0]
CVE-2026-27544
: Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
[CRITICAL 10.0]
CVE-2026-61962
: Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
[CRITICAL 10.0]
CVE-2026-19188
: A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gate
[CRITICAL 10.0]
CVE-2026-73678
: MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution
[CRITICAL 10.0]
CVE-2026-56163
: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-66803
: Azure Cosmos DB Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-56191
: Microsoft Exchange Online Tampering Vulnerability
[CRITICAL 10.0]
CVE-2026-57106
: Data Quality Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-62825
: Azure Key Vault Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-58630
: Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-58275
: Azure DNS Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-42960
: Possible cache poisoning via promiscuous records for the authority section
[CRITICAL 10.0]
CVE-2026-46595
: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
[CRITICAL 10.0]
CVE-2026-39821
: Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
[CRITICAL 10.0]
CVE-2026-40412
: Azure Orbital Spatio Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-23652
: Microsoft Power Pages Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-47280
: Azure Resource Manager Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-42822
: Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-42826
: Azure DevOps Information Disclosure Vulnerability
[CRITICAL 10.0]
CVE-2026-41104
: Microsoft Planetary Computer Pro Information Disclosure Vulnerability
[CRITICAL 10.0]
CVE-2026-42901
: Microsoft Entra ID Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-65041
: Microsoft Partner Center Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-65037
: Azure Container Apps Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-63508
: Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-56162
: Azure SQL Database Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-65667
: Microsoft Teams Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33819
: Microsoft Bing Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-32186
: Microsoft Bing Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33107
: Azure Databricks Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-35431
: Microsoft Entra ID Entitlement Management Spoofing Vulnerability
[CRITICAL 10.0]
CVE-2026-32213
: Azure AI Foundry Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33105
: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-40175
: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
[CRITICAL 10.0]
CVE-2026-45480
: Azure Active Directory Elevation of Privilege Vulnerability
[CRITICAL 10.0]