Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-0257 KEVEPSS 94%
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…
Pan Os
10.2.7+
CRITICAL 9.6
CVE-2026-45321 KEV
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. Th…
Mistralai
Mitigation only
HIGH 8.8
CVE-2026-42271 KEVEPSS 83%
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…
Openshift Ai
1.83.7 / 2.25.8+
CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…
Litellm
1.83.7+
HIGH 7.2
CVE-2026-6973 KEVEPSS 34%
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative…
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.8
CVE-2026-0300 KEVEPSS 32%
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un…
Pan Os
Mitigation only
CRITICAL 9.8
CVE-2026-41940 KEVEPSS 98%
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …
Wp Squared
86.0.41 / 110.0.97+
HIGH 7.8
CVE-2026-31431 KEVEPSS 100%
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commi…
Linux Kernel
4.12.89 / 4.13.66+
HIGH 7.8
CVE-2026-33825 KEVEPSS 7%
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Defender Antimalware Platform
4.18.26030.3011+
CRITICAL 9.8
CVE-2026-33824 KEVEPSS 56%
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 6.5
CVE-2026-32201 KEVEPSS 23%
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20210+
CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…
Fortisandbox
after 4.4.9
HIGH 8.6
CVE-2026-34621 KEVEPSS 7%
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes (…
Acrobat Dc
24.001.30360 / 24.001.30362+
HIGH 7.5
CVE-2026-34486 KEVEPSS 83%
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
…
Tomcat
Mitigation only
CRITICAL 9.8
CVE-2026-39987 KEVEPSS 97%
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…
Marimo
0.23.0+
HIGH 8.8
CVE-2026-34197 KEVEPSS 97%
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apach…
Activemq
5.19.4 / 6.2.3+
CRITICAL 9.8
CVE-2026-35616 KEVEPSS 91%
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized …
Forticlientems
Patch available
HIGH 8.8
CVE-2026-5281 KEV
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra…
Chrome
146.0.7680.177+
HIGH 7.8
CVE-2026-3502 KEVEPSS 6%
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update del…
Trueconf
8.5.3.884+
HIGH 8.8
CVE-2026-33634 KEVEPSS 59%
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push …
Trivy
0.2.6 / 0.35.0+
CRITICAL 9.8
CVE-2026-3055 KEVEPSS 84%
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Netscaler Application Delivery Controller
13.1-37.262 / 13.1-62.23+
CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…
Langflow
1.8.2+
HIGH 8.8
CVE-2026-3910 KEV
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
Chrome
146.0.7680.75+
HIGH 8.8
CVE-2026-3909 KEV
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HT…
Chrome
146.0.7680.80+
CRITICAL 9.8
CVE-2025-67038 KEVEPSS 14%
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. …
Eds5032 Firmware
Mitigation only
CRITICAL 10.0
CVE-2026-20131 KEVEPSS 31%
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot…
Secure Firewall Management Center
Mitigation only
HIGH 7.8
CVE-2026-21385 KEV
Memory corruption while using alignments for memory allocation.
Sm7675p Firmware
Patch available
HIGH 8.1
CVE-2026-22719 KEVEPSS 17%
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm…
Aria Operations
5.2.3 / 8.18.6+
HIGH 7.5
CVE-2026-20133 KEVEPSS 31%
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
HIGH 7.5
CVE-2026-20128 KEVEPSS 7%
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain D…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+