Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-4611
A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file …
X6000r Firmware
Mitigation only
HIGH 7.2
CVE-2026-23882
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…
Blinko
1.8.4+
HIGH 8.8
CVE-2026-33648
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding u…
Avideo
after 26.0
HIGH 7.2
CVE-2025-15518
Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…
Archer Nx600 Firmware
1.3.0 / 1.4.0+
HIGH 7.2
CVE-2025-15519
Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…
Archer Nx600 Firmware
1.3.0 / 1.4.0+
CRITICAL 10.0
CVE-2026-33478EPSS 13%
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…
Avideo
after 26.0
HIGH 8.1
CVE-2026-33482
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/…
Avideo
after 26.0
CRITICAL 9.8
CVE-2026-4585
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy…
Mitigation only
CRITICAL 9.8
CVE-2026-32968
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in …
Mitigation only
HIGH 8.8
CVE-2026-4558
A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipu…
Mr9600 Firmware
No fix yet
HIGH 7.5
CVE-2026-33319
WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin construc…
Avideo
26.0+
HIGH 8.8
CVE-2026-4554
A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The …
F453 Firmware
No fix yet
CRITICAL 9.8
CVE-2026-32056
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac…
Openclaw
2026.2.22+
HIGH 8.1
CVE-2026-33154
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due …
Dynaconf
3.2.13+
HIGH 7.8
CVE-2025-63261
AWStats 8.0 is vulnerable to Command Injection via the open function
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2026-4499
A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le…
Dir 820lw Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-4496
A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function ch…
Patch available
CRITICAL 9.8
CVE-2026-4497
A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…
Wa300 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-22897
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra…
Qunetswitch
2.0.4.0415+
CRITICAL 9.8
CVE-2026-22901
A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne…
Qunetswitch
after 2.0.5.0906
MEDIUM 6.7
CVE-2026-22902
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit …
Qunetswitch
after 2.0.5.0906
HIGH 8.8
CVE-2026-32950
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab…
Sqlbot
1.7.0+
HIGH 8.8
CVE-2026-4465
A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of…
Dir 513 Firmware
No fix yet
HIGH 8.1
CVE-2026-32034
OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an…
Openclaw
2026.2.21+
HIGH 8.8
CVE-2026-32010
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exe…
Openclaw
2026.2.22+
HIGH 7.2
CVE-2026-32003
OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypa…
Openclaw
2026.2.22+
CRITICAL 9.8
CVE-2026-32191
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…
Bing Images
Mitigation only
CRITICAL 9.1
CVE-2026-32238
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command …
Openemr
8.0.0.2+
HIGH 7.8
CVE-2026-31999
OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.…
Openclaw
2026.3.1+
HIGH 7.1
CVE-2026-32000
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallba…
Openclaw
2026.2.19+