Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-42047
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 thr…
Inngest
3.54.0+
MEDIUM 5.3
CVE-2026-8033
A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ …
Mitigation only
HIGH 7.5
CVE-2026-34474EPSS 25%
Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can …
Mitigation only
HIGH 8.8
CVE-2025-52613
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e…
Bigfix Service Management
Mitigation only
MEDIUM 5.4
CVE-2025-31984
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…
Bigfix Service Management
Mitigation only
HIGH 7.5
CVE-2025-31976
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31982
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31975
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2026-8026
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv…
Flowise
after 3.0.12
HIGH 7.5
CVE-2026-43646
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17…
Wicket
10.9.0+
HIGH 7.7
CVE-2026-36355
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks …
Mitigation only
MEDIUM 6.5
CVE-2026-4409
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a …
Mitigation only
MEDIUM 6.5
CVE-2026-42223
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) seria…
Nginx Ui
2.3.8+
MEDIUM 6.5
CVE-2026-42220
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sens…
Nginx Ui
2.3.8+
HIGH 7.5
CVE-2026-42151
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD …
Prometheus
3.5.3 / 3.11.3+
MEDIUM 6.5
CVE-2026-42092
titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admi…
Mitigation only
MEDIUM 5.3
CVE-2026-3504
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio…
Mitigation only
MEDIUM 6.5
CVE-2025-14726
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capabil…
Mitigation only
MEDIUM 6.5
CVE-2026-7382
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare…
Mitigation only
CRITICAL 9.1
CVE-2026-7381
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.
Plack::Middleware::XSendfile allows the va…
Plack\
after 1.0053
MEDIUM 5.3
CVE-2026-7071
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file…
Mitigation only
CRITICAL 9.8
CVE-2026-41492
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v…
Dgraph
25.3.3+
MEDIUM 5.4
CVE-2026-41079
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can…
Cups
2.4.17+
CRITICAL 9.9
CVE-2026-21515
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
Azure Iot Central
No fix yet
CRITICAL 9.1
CVE-2026-41323
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…
Kyverno
1.16.4 / 1.17.2+
HIGH 7.5
CVE-2026-41278
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoin…
Flowise
3.1.0+
HIGH 7.5
CVE-2026-41266
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …
Flowise
3.1.0+
MEDIUM 5.3
CVE-2026-4106
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, …
Mitigation only
MEDIUM 5.3
CVE-2026-41182
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of …
Mitigation only
HIGH 7.5
CVE-2026-40895
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, …
Follow Redirects
1.16.0+