Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-27959
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of th…
Koa
2.16.4 / 3.1.2+
HIGH 7.5
CVE-2026-27818
TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions pri…
Terriajs Server
4.0.3+
HIGH 8.1
CVE-2026-25941
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 …
Freerdp
2.11.8 / 3.23.0+
CRITICAL 9.0
CVE-2026-27702
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…
Budibase
3.30.4+
CRITICAL 9.1
CVE-2026-27607
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…
Rustfs
Mitigation only
HIGH 7.8
CVE-2025-14963
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system p…
Endpoint Security
after 34.0.0
CRITICAL 9.8
CVE-2026-27590
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…
Caddy
2.11.1+
MEDIUM 6.5
CVE-2026-27585
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanit…
Caddy
2.11.1+
HIGH 7.5
CVE-2026-27642
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…
Udm
after 1.4.1
HIGH 7.5
CVE-2026-21864
Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co…
Valkey Bloom
1.0.1+
HIGH 7.5
CVE-2025-69250
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…
Udm
after 1.4.1
MEDIUM 5.3
CVE-2025-69251
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…
Udm
after 1.4.1
HIGH 7.5
CVE-2025-69232
free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to f…
Go Upf
after 1.4.0
HIGH 7.5
CVE-2026-27623
Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…
Valkey
9.0.3+
HIGH 7.5
CVE-2026-2970
A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-…
Datapizza Ai
No fix yet
MEDIUM 6.5
CVE-2026-2898
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p…
Funadmin
7.1.0+
HIGH 7.1
CVE-2026-27170
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest…
Opensift
1.1.3+
MEDIUM 5.4
CVE-2026-26952
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below…
Web Interface
6.4.1+
MEDIUM 5.4
CVE-2026-26953
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and abov…
Web Interface
6.4.1+
HIGH 7.5
CVE-2026-26314
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to s…
Go Ethereum
1.16.9+
HIGH 8.8
CVE-2026-26063
CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validatio…
Mitigation only
MEDIUM 6.5
CVE-2025-13587
The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including…
Mitigation only
HIGH 7.5
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o…
Tomcat
1.3.5 / 2.0.12+
CRITICAL 9.1
CVE-2025-66614
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…
Tomcat
9.0.113 / 10.1.50+
HIGH 7.5
CVE-2026-2555
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/…
Jeecg Boot
No fix yet
HIGH 7.5
CVE-2025-70123
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF in…
Free5gc
No fix yet
HIGH 7.5
CVE-2026-2391
### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cau…
Qs
6.14.2+
MEDIUM 5.5
CVE-2026-20627
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPa…
Ipados
14.8.4 / 26.3+
MEDIUM 5.5
CVE-2026-21258
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.10417.20097+
HIGH 7.3
CVE-2026-21247
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+