Live disclosure tracker · updated continuously

Technology & Software Data Breaches

SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.

98B+
Records Exposed
1270
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

Technology & Software Data Breaches (1270 indexed)

high · tech · Dec 15, 2025

Apple Multiple Products

Apple Multiple Products Use-After-Free WebKit Vulnerability — Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to me

View incident → Original disclosure Indexed 5 months, 1 week ago
high · tech · Dec 15, 2025

Gladinet CentreStack and Triofox

Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability — Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulne

View incident → Original disclosure Indexed 5 months, 1 week ago
high · tech · Dec 12, 2025

Google Chromium

Google Chromium Out of Bounds Memory Access Vulnerability — Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a c

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 12, 2025

Sierra Wireless AirLink ALEOS

Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability — Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted H

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 11, 2025

OSGeo GeoServer

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability — OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accep

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 9, 2025

RARLAB WinRAR

RARLAB WinRAR Path Traversal Vulnerability — RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 9, 2025

Microsoft Windows

Microsoft Windows Use After Free Vulnerability — Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 8, 2025

D-Link Routers

D-Link Routers Buffer Overflow Vulnerability — D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (E

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Dec 8, 2025

Array Networks ArrayOS AG

Array Networks ArrayOS AG OS Command Injection Vulnerability — Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

View incident → Original disclosure Indexed 5 months, 2 weeks ago
critical · tech · Dec 5, 2025

Meta React Server Components

Meta React Server Components Remote Code Execution Vulnerability — Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw i

View incident → Original disclosure Indexed 5 months, 3 weeks ago
high · tech · Dec 3, 2025

OpenPLC ScadaBR

OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability — OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload a

View incident → Original disclosure Indexed 5 months, 3 weeks ago
high · tech · Nov 21, 2025

Oracle Fusion Middleware

Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attack