Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2026-22686
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in…
Enclave
2.7.0+
HIGH 7.2
CVE-2022-50806
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template …
4images
No fix yet
CRITICAL 9.8
CVE-2026-22869
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution fr…
Eigent
0.0.78+
HIGH 8.8
CVE-2025-41717
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to cod…
Mitigation only
HIGH 7.2
CVE-2026-0498
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC…
S\/4 Hana
Patch available
HIGH 8.8
CVE-2026-0500
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat…
Introscope Enterprise Manager
Patch available
CRITICAL 9.1
CVE-2026-0491
SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en…
Mitigation only
HIGH 8.8
CVE-2026-22771
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, E…
Gateway
1.5.7 / 1.6.2+
CRITICAL 9.8
CVE-2026-22584
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code…
Uni2ts
2.0.0+
CRITICAL 9.3
CVE-2020-36875
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl…
Mitigation only
CRITICAL 9.8
CVE-2025-66913
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke…
Jimureport
after 2.1.3
CRITICAL 9.4
CVE-2025-66916
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres…
Ruoyi Vue Plus
after 5.5.1
HIGH 7.2
CVE-2026-22244
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SST…
Openmetadata
1.11.4+
CRITICAL 9.9
CVE-2026-21877EPSS 5%
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…
N8n
1.121.3+
HIGH 7.8
CVE-2025-69262
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np…
Pnpm
10.27.0+
MEDIUM 6.1
CVE-2026-0642
A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/comp…
House Rental And Property Listing Project
No fix yet
MEDIUM 5.0
CVE-2024-14020
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/…
Patch available
CRITICAL 9.6
CVE-2025-55204
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.…
Muffon
2.3.0+
MEDIUM 6.1
CVE-2026-0588
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.p…
Rockoa
after 2.7.1
MEDIUM 6.1
CVE-2026-0586
A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file handgunn…
Online Product Reservation System
No fix yet
MEDIUM 5.4
CVE-2026-0587
A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the compo…
Rockoa
after 2.7.1
MEDIUM 6.1
CVE-2026-0580
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Impo…
Api Key Manager App
Mitigation only
CRITICAL 9.8
CVE-2025-11837
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulner…
Malware Remover
6.6.8.20251023+
MEDIUM 5.4
CVE-2025-15437
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manip…
Ligerosmart
after 6.1.24
MEDIUM 5.4
CVE-2025-15416
A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Var…
Wangmarket
after 6.4
HIGH 7.2
CVE-2025-68619
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators…
Signal K Server
2.19.0+
HIGH 8.8
CVE-2025-15393
A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/…
Kodicms
after 13.82.135
HIGH 7.2
CVE-2025-15394
A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parame…
Icms
after 8.0.0
MEDIUM 5.4
CVE-2025-15374
A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co…
Eyoucms
1.7.8+
MEDIUM 6.1
CVE-2025-15223
A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an unknown function of the file /…
Simple Php Blog
after 2025-01-22