Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-30460
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
Fuel Cms
No fix yet
CRITICAL 9.8
CVE-2024-36057
Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $…
Mitigation only
HIGH 7.2
CVE-2026-22666EPSS 16%
Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails…
Dolibarr Erp\/crm
23.0.2+
HIGH 8.8
CVE-2026-34197 KEVEPSS 97%
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apach…
Activemq
5.19.4 / 6.2.3+
CRITICAL 9.8
CVE-2026-35197
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbit…
Dye
Mitigation only
CRITICAL 9.8
CVE-2026-35178
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0…
Forceworkbench
65.0.0+
CRITICAL 9.8
CVE-2026-35171
Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…
Kedro
1.3.0+
HIGH 7.2
CVE-2026-26026EPSS 11%
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulne…
Glpi
11.0.6+
HIGH 7.3
CVE-2026-5631
A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/s…
Mitigation only
MEDIUM 6.3
CVE-2026-5594
A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.p…
No fix yet
CRITICAL 9.8
CVE-2026-5584
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py…
Agenticseek
Mitigation only
CRITICAL 9.8
CVE-2026-5562
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutio…
Ui
after 0.7.2
MEDIUM 6.3
CVE-2026-5556
A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the…
Mitigation only
MEDIUM 6.5
CVE-2026-3309
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…
Mitigation only
HIGH 8.8
CVE-2026-28797
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab…
Ragflow
after 0.24.0
MEDIUM 5.4
CVE-2026-5468
A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument …
Casdoor
Mitigation only
HIGH 8.2
CVE-2026-34725
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c…
Patch available
MEDIUM 6.1
CVE-2026-5332
A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. Th…
Panel
Mitigation only
HIGH 8.8
CVE-2026-2701EPSS 57%
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Sharefile Storage Zones Controller
5.12.4+
HIGH 7.2
CVE-2026-1540
The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to …
Mitigation only
CRITICAL 9.8
CVE-2026-30643
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
Dedecms
after 5.7.118
CRITICAL 9.8
CVE-2024-40489
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary…
Jeecg Boot
after 3.5.3
HIGH 8.8
CVE-2026-35093
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directorie…
Fedora
1.30.3 / 1.31.1+
CRITICAL 9.8
CVE-2026-29014EPSS 42%
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary …
Metinfo
Mitigation only
MEDIUM 6.1
CVE-2026-5255
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component …
Simple Laundry System
No fix yet
HIGH 7.2
CVE-2026-35056
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel …
Xenforo
2.2.18 / 2.3.9+
CRITICAL 9.8
CVE-2025-71281
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor…
Xenforo
2.3.7+
HIGH 8.2
CVE-2026-34585
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side…
Siyuan
3.6.2+
CRITICAL 9.0
CVE-2026-34448
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field …
Siyuan
3.6.2+
CRITICAL 9.8
CVE-2026-4800
Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di…
Lodash
4.18.0+