Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-30457
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Dwoo
Mitigation only
MEDIUM 6.1
CVE-2026-4849
A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component …
Simple Laundry System
No fix yet
HIGH 8.8
CVE-2026-33660
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create o…
N8n
1.123.27 / 2.13.3+
CRITICAL 9.1
CVE-2026-32573
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi…
Mitigation only
CRITICAL 9.9
CVE-2026-32525
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue…
Mitigation only
CRITICAL 9.9
CVE-2026-27044
Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.Thi…
Mitigation only
CRITICAL 9.1
CVE-2026-25447
Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.…
Mitigation only
CRITICAL 9.9
CVE-2026-25366
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue af…
Mitigation only
HIGH 8.5
CVE-2026-25001
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This i…
Mitigation only
CRITICAL 9.8
CVE-2026-26831
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious…
Textract
after 2.5.0
CRITICAL 9.8
CVE-2026-26833
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c…
Thumbler
after 1.1.2
CRITICAL 9.8
CVE-2026-26830
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon…
Pdf Image
after 2.0.0
CRITICAL 9.6
CVE-2026-33334
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…
Vikunja
2.2.2+
HIGH 8.8
CVE-2026-33336
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…
Vikunja
2.2.2+
HIGH 8.8
CVE-2026-33310
Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default v…
Intake
2.0.9+
CRITICAL 9.9
CVE-2026-33309EPSS 11%
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…
Langflow
1.9.0+
CRITICAL 10.0
CVE-2026-4745
Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is as…
Patch available
MEDIUM 5.4
CVE-2026-4626
A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m…
Online Lawyer Management System
No fix yet
CRITICAL 9.3
CVE-2026-4681
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…
Mitigation only
HIGH 8.8
CVE-2026-32276
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…
Connect Cms
1.41.1 / 2.41.1+
MEDIUM 5.4
CVE-2026-4596
A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. Th…
Online Lawyer Management System
No fix yet
HIGH 8.8
CVE-2026-24516
A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshootin…
Mitigation only
HIGH 8.8
CVE-2026-33479
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsaniti…
Avideo
after 26.0
HIGH 7.3
CVE-2025-10679
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to a…
Mitigation only
MEDIUM 6.3
CVE-2026-4515
A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/script…
Metagpt
after 0.8.1
MEDIUM 6.5
CVE-2026-4004
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and includin…
Mitigation only
MEDIUM 5.6
CVE-2024-13785
The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions…
Mitigation only
CRITICAL 9.8
CVE-2026-3584EPSS 7%
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio…
Mitigation only
MEDIUM 6.3
CVE-2026-4506
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing …
Mitigation only
HIGH 8.1
CVE-2026-33154
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due …
Dynaconf
3.2.13+