Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.6
CVE-2026-12294
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, a…
Firefox
115.37.0 / 140.12.0+
CRITICAL 9.9
CVE-2026-40750
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.
This is…
Mitigation only
CRITICAL 9.3
CVE-2026-52715
Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Mitigation only
CRITICAL 9.9
CVE-2026-49774
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion.
This issue affects R…
Mitigation only
CRITICAL 9.3
CVE-2026-49772
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allo…
Mitigation only
CRITICAL 9.3
CVE-2026-39574
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-9261
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Eos Network Setting Tool
1.5.1+
CRITICAL 9.8
CVE-2026-9260
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Eos Network Setting Tool
1.5.1+
CRITICAL 9.8
CVE-2026-9259
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Eos Network Setting Tool
1.5.1+
CRITICAL 9.8
CVE-2026-9258
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Eos Network Setting Tool
1.5.1+
CRITICAL 9.2
CVE-2026-48853
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated …
Patch available
CRITICAL 9.1
CVE-2026-12205
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery.
Crypt::DSA::sign caches the per-signat…
Mitigation only
CRITICAL 9.1
CVE-2026-48714
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7,…
I18next Http Middleware
3.9.7+
CRITICAL 9.1
CVE-2026-48713
Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via…
I18next Fs Backend
2.6.6+
CRITICAL 9.1
CVE-2026-12087
Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument …
Patch available
CRITICAL 9.1
CVE-2026-11832
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.
The default nonce was generated using an MD5 hash of the …
Mitigation only
CRITICAL 9.8
CVE-2026-9691
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
Mitigation only
CRITICAL 9.6
CVE-2026-52703
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-52693
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49781
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-49776
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49770
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49769
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49768
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
Mitigation only
CRITICAL 9.9
CVE-2026-49766
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49765
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49764
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49763
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49109
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-49106
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
Mitigation only