Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-25887
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…
Chartbrew
4.8.1+
HIGH 8.8
CVE-2026-25888
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…
Chartbrew
4.8.1+
HIGH 8.8
CVE-2025-70995
An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation…
Mitigation only
HIGH 8.5
CVE-2026-28134
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue af…
Mitigation only
CRITICAL 9.0
CVE-2026-27984
Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is…
Mitigation only
CRITICAL 9.9
CVE-2026-22390
Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allo…
Mitigation only
CRITICAL 9.1
CVE-2026-28783
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou…
Craft Cms
4.17.0 / 5.9.0+
HIGH 8.1
CVE-2026-23808
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled…
Arubaos
after 10.7.2.2
HIGH 7.8
CVE-2025-70341
Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
App Auto Patch
after 3.4.2
HIGH 8.8
CVE-2024-55022
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet…
Easyweb
Mitigation only
HIGH 8.8
CVE-2023-31044
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio…
Impact Mobile
after 23
CRITICAL 9.8
CVE-2025-59059
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to…
Ranger
2.8.0+
HIGH 8.8
CVE-2026-21853
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerabi…
Affine
0.25.4+
HIGH 8.8
CVE-2026-3132
The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via t…
Mitigation only
CRITICAL 9.8
CVE-2026-24105
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a …
Ac15 Firmware
Mitigation only
HIGH 7.2
CVE-2026-26699
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.
Personnel Property Equipment System
No fix yet
CRITICAL 9.8
CVE-2026-26720
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
Twenty
after 1.15.0
CRITICAL 9.8
CVE-2026-24107
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`…
W20e Firmware
Mitigation only
MEDIUM 6.1
CVE-2026-3412
A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The man…
University Management System
No fix yet
HIGH 7.3
CVE-2026-3409
A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the fi…
Mitigation only
CRITICAL 9.8
CVE-2026-3395
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…
Maxsite Cms
109.2+
HIGH 8.0
CVE-2026-28425
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with…
Statamic
5.73.11 / 6.4.0+
CRITICAL 9.8
CVE-2026-21656
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21657
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21658
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …
Frick Controls Quantum Hd Firmware
after 10.22
MEDIUM 6.1
CVE-2026-3302
A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /reg…
Doctor Appointment System
No fix yet
HIGH 7.8
CVE-2026-26682
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component
Fastcms
0.1.6+
CRITICAL 9.8
CVE-2026-27966EPSS 34%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo…
Langflow
1.8.0+
CRITICAL 9.9
CVE-2026-27952
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod…
Agenta
0.48.1+
HIGH 8.0
CVE-2026-27830
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instanc…
Patch available