Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-44722
SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
Sysak
after 2.0
CRITICAL 9.8
CVE-2026-33057EPSS 5%
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai…
Mesop
1.2.3+
MEDIUM 6.1
CVE-2026-4474
A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.…
University Management System
No fix yet
CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…
Langflow
1.8.2+
HIGH 8.8
CVE-2026-29102
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Auth…
Suitecrm
7.15.1 / 8.9.3+
HIGH 7.2
CVE-2026-29103
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vuln…
Suitecrm
7.15.1 / 8.9.3+
CRITICAL 9.8
CVE-2026-30694
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
Dedecms
after 5.7.118
CRITICAL 9.8
CVE-2025-67113
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo…
Mitigation only
CRITICAL 9.8
CVE-2026-30402
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function
Wgcloud
after 2.3.7
MEDIUM 6.5
CVE-2026-31898
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to…
Jspdf
4.2.1+
HIGH 8.8
CVE-2026-21570
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 1…
Bamboo
9.6.24 / 10.2.16+
CRITICAL 9.8
CVE-2025-69902
A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via…
Mitigation only
HIGH 8.8
CVE-2025-50881
The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET re…
Mitigation only
HIGH 8.8
CVE-2026-30875
Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authen…
Chamilo Lms
1.11.36+
HIGH 7.5
CVE-2026-4276
LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
Librechat
Mitigation only
HIGH 7.8
CVE-2026-3476
A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code …
Solidworks
2026+
MEDIUM 6.4
CVE-2026-32719
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th…
Anythingllm
after 1.11.1
CRITICAL 9.8
CVE-2026-32640
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul…
Simpleeval
1.0.5+
HIGH 8.8
CVE-2025-14287
A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 16…
Mlflow
3.7.0+
HIGH 8.8
CVE-2025-15540
"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or acc…
Raytha
1.4.6+
HIGH 8.8
CVE-2026-3910 KEV
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
Chrome
146.0.7680.75+
HIGH 7.2
CVE-2026-32414
Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion…
Mitigation only
CRITICAL 9.1
CVE-2026-32367
Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th…
Mitigation only
CRITICAL 9.8
CVE-2026-32304
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…
Locutus
3.0.14+
CRITICAL 10.0
CVE-2026-26954
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox…
Sandboxjs
0.8.34+
HIGH 8.8
CVE-2026-25817
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improp…
Mitigation only
CRITICAL 9.9
CVE-2026-21669
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Veeam Backup \& Replication
13.0.1.2067+
CRITICAL 9.1
CVE-2026-21671
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) de…
Veeam Backup \& Replication
after 13.0.1.1071
HIGH 8.8
CVE-2026-4039
A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill E…
Openclaw
2026.2.21+
MEDIUM 6.3
CVE-2026-3968
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of …
Mitigation only