Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-78211
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malic…
No fix yet
CRITICAL 9.9
CVE-2026-78169
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempS…
No fix yet
CRITICAL 9.8
CVE-2026-78168
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component …
No fix yet
CRITICAL 10.0
CVE-2026-78167
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session…
No fix yet
CRITICAL 9.4
CVE-2026-78207
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or pr…
No fix yet
CRITICAL 9.8
CVE-2026-8445
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a…
No fix yet
CRITICAL 9.8
CVE-2026-7808
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s…
No fix yet
CRITICAL 9.8
CVE-2026-5388
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma…
No fix yet
CRITICAL 9.9
CVE-2026-78155
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
No fix yet
CRITICAL 9.9
CVE-2026-78050
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&sec…
No fix yet
CRITICAL 9.8
CVE-2026-4703
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …
No fix yet
CRITICAL 9.5
CVE-2026-77992
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform an…
No fix yet
CRITICAL 10.0
CVE-2026-76607
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76606
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76605
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76604
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable t…
No fix yet
CRITICAL 9.3
CVE-2026-76602
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries…
No fix yet
CRITICAL 9.3
CVE-2026-76571
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed…
No fix yet
CRITICAL 10.0
CVE-2026-77946
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app…
No fix yet
CRITICAL 9.8
CVE-2026-78003
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including…
No fix yet
CRITICAL 9.3
CVE-2026-12710
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows …
No fix yet
CRITICAL 9.8
CVE-2026-77002
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, …
No fix yet
CRITICAL 9.8
CVE-2026-77001
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no…
No fix yet
CRITICAL 9.8
CVE-2026-77000
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before…
No fix yet
CRITICAL 9.1
CVE-2026-49849
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr…
Patch available
CRITICAL 9.3
CVE-2026-77415
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn…
Patch available
CRITICAL 9.3
CVE-2026-77414
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw…
Patch available
CRITICAL 9.3
CVE-2026-77413
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn…
Patch available
CRITICAL 9.8
CVE-2026-76904
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,…
Patch available
CRITICAL 9.9
CVE-2026-62283
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro…
Patch available