Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-34202
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p…
Zebra
4.3.0 / 6.0.1+
CRITICAL 9.8
CVE-2026-34060
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub…
Ruby Lsp
0.10.2 / 0.26.9+
CRITICAL 9.8
CVE-2026-3300EPSS 41%
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12…
Mitigation only
CRITICAL 9.8
CVE-2026-4257EPSS 41%
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in a…
Mitigation only
CRITICAL 9.8
CVE-2026-30308
In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. …
Hai Build
after 3.13.3
CRITICAL 9.8
CVE-2026-30313
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…
Cline
after 1.1.2
CRITICAL 9.8
CVE-2026-30306
In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description f…
Sakadev
4.0.6+
CRITICAL 9.8
CVE-2026-30305
Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely …
Syntx
after 2.5.0
CRITICAL 9.8
CVE-2026-30307
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism complete…
Roo Code
after 3.46.1
CRITICAL 10.0
CVE-2026-28505
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handl…
Tautulli
2.17.0+
CRITICAL 9.8
CVE-2026-2287
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
Crewai
Mitigation only
MEDIUM 6.3
CVE-2026-5011
A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component J…
Mitigation only
HIGH 7.3
CVE-2026-4998
A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai…
Mitigation only
HIGH 8.6
CVE-2026-33955
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi…
Notesnook Desktop
3.3.11+
CRITICAL 9.6
CVE-2026-33976
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can …
Notesnook Desktop
3.3.11 / 3.3.17+
HIGH 8.1
CVE-2026-33940
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa…
Handlebars
4.7.9+
HIGH 8.2
CVE-2026-33941
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…
Handlebars
4.7.9+
CRITICAL 9.8
CVE-2026-33943
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection …
Happy Dom
20.8.8+
CRITICAL 9.8
CVE-2026-33937
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…
Handlebars
4.7.9+
HIGH 8.1
CVE-2026-33938
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable…
Handlebars
4.7.9+
HIGH 7.2
CVE-2026-33881
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are …
Windmill
1.664.0+
CRITICAL 9.9
CVE-2026-33873
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec…
Langflow
1.9.0+
CRITICAL 9.8
CVE-2026-33654
nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module …
Nanobot
0.1.4+
CRITICAL 9.8
CVE-2026-4965
A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the…
Letta
Mitigation only
CRITICAL 10.0
CVE-2026-4963
A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the…
Smolagents
Mitigation only
HIGH 7.2
CVE-2025-15616
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow…
Wazuh
4.8.0+
CRITICAL 9.1
CVE-2026-27876
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…
Grafana
11.6.0 / 12.0.0+
CRITICAL 9.8
CVE-2026-32669
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr…
Wcr 1166dhpl Firmware
1.01 / 2.53+
HIGH 7.8
CVE-2026-33744
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packag…
Bentoml
1.4.37+
HIGH 8.8
CVE-2026-33622
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary Ja…
Pinchtab
after 0.8.5