Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2021-47940
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers t…
Mitigation only
CRITICAL 9.8
CVE-2021-47933
WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending…
Mitigation only
CRITICAL 9.8
CVE-2021-47936
OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malici…
Mitigation only
CRITICAL 9.4
CVE-2026-42569
phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access…
Patch available
MEDIUM 6.3
CVE-2026-8185
A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative I…
Mitigation only
CRITICAL 9.8
CVE-2026-42302
FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to una…
Patch available
MEDIUM 6.7
CVE-2026-42176
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified thro…
Mitigation only
HIGH 7.3
CVE-2026-44338EPSS 29%
PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication d…
Praisonai
4.6.34+
MEDIUM 6.5
CVE-2026-6736
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user acc…
Enterprise Server
3.16.18 / 3.17.15+
CRITICAL 9.8
CVE-2026-7415
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th…
Lawn Mower Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-8031
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs…
Mitigation only
CRITICAL 9.8
CVE-2026-41930
Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthentica…
Patch available
MEDIUM 6.3
CVE-2026-7844
A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_fi…
Mitigation only
CRITICAL 9.1
CVE-2026-36356EPSS 14%
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via …
Mitigation only
CRITICAL 9.8
CVE-2023-54344
Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary comm…
Mitigation only
CRITICAL 9.8
CVE-2023-54342
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated att…
Mitigation only
CRITICAL 9.8
CVE-2026-42221
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim …
Nginx Ui
2.3.8+
CRITICAL 9.8
CVE-2026-42222
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init…
Nginx Ui
Mitigation only
CRITICAL 9.8
CVE-2026-42796
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que…
Arelle
2.39.10+
HIGH 7.3
CVE-2026-7723
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoi…
Patch available
MEDIUM 6.5
CVE-2026-7714
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_f…
Patch available
CRITICAL 10.0
CVE-2026-39858
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass…
Traefik
2.11.43 / 3.6.14+
MEDIUM 6.5
CVE-2026-35514
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the …
Mitigation only
CRITICAL 9.8
CVE-2025-13030
All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker …
Django Mdeditor
Patch available
HIGH 8.0
CVE-2026-0204
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific condition…
Sonicos
6.5.5.2-28n / 7.3.2-7010+
CRITICAL 9.8
CVE-2026-41940 KEVEPSS 98%
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …
Wp Squared
86.0.41 / 110.0.97+
CRITICAL 9.4
CVE-2026-3893
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism,
allowing an attacker with network access to directly access and modify
its con…
Mitigation only
HIGH 8.2
CVE-2026-5944
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth…
Intersight Device Connector
after 7.5.0
HIGH 7.5
CVE-2026-3323
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed cr…
Vegapuls 6x Firmware
Mitigation only
HIGH 7.4
CVE-2026-41603
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+