Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-9208
Tanium addressed an unauthorized code execution vulnerability in Connect.
Connect
5.26.191 / 5.29.237+
HIGH 7.8
CVE-2026-45152
uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe …
Mitigation only
HIGH 8.2
CVE-2026-44712
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the confi…
Mitigation only
HIGH 8.8
CVE-2026-44713
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment vari…
Mitigation only
HIGH 7.8
CVE-2026-45136
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) int…
Claude Code Cache Fix
3.5.2+
HIGH 7.8
CVE-2026-44709
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP en…
Mitigation only
CRITICAL 9.3
CVE-2026-44590
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.…
Mitigation only
HIGH 7.8
CVE-2026-44724
systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command inj…
Mitigation only
CRITICAL 10.0
CVE-2026-45087
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf…
Mitigation only
HIGH 8.8
CVE-2026-44345
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/con…
Bentoml
1.4.39+
HIGH 8.8
CVE-2026-44346
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam…
Bentoml
1.4.39+
HIGH 8.8
CVE-2026-36044
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/…
Mitigation only
HIGH 7.3
CVE-2026-36045
picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function atte…
Mitigation only
HIGH 7.2
CVE-2026-40852
A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly ch…
Mitigation only
CRITICAL 9.1
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().
send_file() opens its string argument with Perl's 2-arg open(…
Patch available
HIGH 8.8
CVE-2026-9207
Tanium addressed an unauthorized code execution vulnerability in Connect.
Connect
5.26.191 / 5.29.237+
CRITICAL 9.1
CVE-2026-44444
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts…
Mitigation only
HIGH 7.8
CVE-2026-9560
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with eleva…
Connect
3.8.2+
CRITICAL 9.9
CVE-2026-46624
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL …
Twenty
1.16.7+
HIGH 8.1
CVE-2026-48694
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_…
Fastnetmon
after 1.2.9
HIGH 8.1
CVE-2026-48695
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() funct…
Fastnetmon
after 1.2.9
MEDIUM 6.3
CVE-2026-9565
A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/age…
Mitigation only
CRITICAL 9.9
CVE-2026-44723
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly i…
Vowpal Wabbit
2026-05-04+
CRITICAL 9.8
CVE-2026-48687
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() functi…
Fastnetmon
after 1.2.9
CRITICAL 9.0
CVE-2026-4480EPSS 14%
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…
Openshift Container Platform
4.2.1+
CRITICAL 9.8
CVE-2026-9543
A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of th…
Mitigation only
MEDIUM 6.3
CVE-2026-9532EPSS 11%
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bi…
Mitigation only
MEDIUM 6.3
CVE-2026-9533EPSS 11%
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi o…
Mitigation only
MEDIUM 6.3
CVE-2026-9534EPSS 11%
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Se…
Mitigation only
MEDIUM 6.3
CVE-2026-9531EPSS 11%
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the compo…
Mitigation only