Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.7
CVE-2026-73651
TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Pri…
No fix yet
CRITICAL 9.8
CVE-2026-73649
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr…
No fix yet
HIGH 7.8
CVE-2026-73505
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/p…
No fix yet
HIGH 8.4
CVE-2026-67986
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A…
No fix yet
CRITICAL 10.0
CVE-2026-61962
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
No fix yet
CRITICAL 10.0
CVE-2026-27544
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
No fix yet
CRITICAL 9.0
CVE-2026-73487
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…
No fix yet
CRITICAL 9.0
CVE-2026-73485
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…
No fix yet
CRITICAL 9.0
CVE-2026-73486
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…
No fix yet
MEDIUM 5.2
CVE-2026-0298
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ …
No fix yet
HIGH 7.8
CVE-2026-13094
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi…
I Access Client Solutions
No fix yet
CRITICAL 9.9
CVE-2026-73268
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat…
No fix yet
CRITICAL 10.0
CVE-2026-73299
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .…
No fix yet
HIGH 8.8
CVE-2026-65941
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…
No fix yet
HIGH 7.1
CVE-2026-73291
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im…
No fix yet
CRITICAL 10.0
CVE-2026-67282
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code …
No fix yet
CRITICAL 9.8
CVE-2026-16051
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no…
No fix yet
HIGH 8.5
CVE-2026-73248
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or …
No fix yet
CRITICAL 9.4
CVE-2026-66147
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…
No fix yet
MEDIUM 6.3
CVE-2026-66148
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…
No fix yet
HIGH 7.8
CVE-2026-66149
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
HIGH 7.8
CVE-2026-66150
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…
No fix yet
HIGH 8.5
CVE-2026-73233
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui…
No fix yet
CRITICAL 9.6
CVE-2026-73032
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou…
No fix yet
CRITICAL 9.1
CVE-2026-66145
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…
No fix yet
CRITICAL 10.0
CVE-2026-45618
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…
No fix yet
MEDIUM 6.4
CVE-2026-18708
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe…
No fix yet
MEDIUM 6.1
CVE-2026-73084
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c…
No fix yet
HIGH 8.8
CVE-2026-70336
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
1.132.1+
HIGH 7.8
CVE-2026-70338
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…
Powershell
7.4.19.0 / 7.5.10.0+