Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a net…
Sharepoint Server
16.0.19725.20522+
HIGH 8.4
CVE-2026-73076
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord…
No fix yet
HIGH 8.8
CVE-2026-19546
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.
For a detailed Statement, Description and Mit…
No fix yet
HIGH 8.7
CVE-2026-72765
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create …
No fix yet
CRITICAL 10.0
CVE-2026-58231
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain function…
No fix yet
CRITICAL 9.1
CVE-2026-44758
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu…
No fix yet
CRITICAL 9.3
CVE-2026-72904
Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …
No fix yet
MEDIUM 5.5
CVE-2026-18942
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by …
No fix yet
HIGH 8.8
CVE-2026-66738
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-type…
No fix yet
HIGH 7.0
CVE-2026-72718
goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather t…
No fix yet
CRITICAL 9.8
CVE-2026-42537
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-44416
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0.
Users are recommended to upgra…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-55799
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fi…
Ranger
No fix yet
CRITICAL 10.0
CVE-2026-66915
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the aja…
No fix yet
CRITICAL 9.6
CVE-2026-46409
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…
No fix yet
HIGH 8.7
CVE-2026-17603
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A us…
No fix yet
MEDIUM 5.3
CVE-2026-50159
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulne…
No fix yet
HIGH 8.8
CVE-2026-48054
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to …
No fix yet
MEDIUM 5.3
CVE-2026-19060
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. …
No fix yet
MEDIUM 5.3
CVE-2026-19058
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/…
No fix yet
CRITICAL 9.1
CVE-2026-66709
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
No fix yet
CRITICAL 10.0
CVE-2026-65553
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
No fix yet
CRITICAL 9.9
CVE-2026-65548
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
No fix yet
CRITICAL 9.3
CVE-2026-67531
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host …
No fix yet
CRITICAL 9.6
CVE-2026-71319
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…
No fix yet
HIGH 8.1
CVE-2026-71320
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nux…
No fix yet
HIGH 7.8
CVE-2026-55522
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow…
No fix yet
HIGH 8.8
CVE-2026-9196
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp…
Langflow
1.11.0+
HIGH 8.8
CVE-2026-8478
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…
Langflow
1.11.0+
HIGH 8.8
CVE-2026-8182
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via …
Langflow
1.11.0+