Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-47291EPSS 23%
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.8
CVE-2026-45657EPSS 15%
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.20348.5256 / 10.0.22631.7219+
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
CRITICAL 9.1
CVE-2026-45602
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.8
CVE-2026-44815
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.6
CVE-2026-42904
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
Windows 10 21h2
10.0.19044.7417 / 10.0.19045.7417+
CRITICAL 9.8
CVE-2026-38615
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Mitigation only
CRITICAL 9.1
CVE-2026-34182
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
sufficient input validation on the cipher and tag length fields of
Au…
OpenSSL
3.0.21 / 3.4.6+
CRITICAL 9.8
CVE-2026-26142
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Nuance Powerscribe 360
Mitigation only
CRITICAL 9.8
CVE-2026-8025
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform…
Mitigation only
CRITICAL 9.8
CVE-2026-25089 KEVEPSS 76%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…
Fortisandbox
4.4.9 / 5.0.6+
CRITICAL 9.8
CVE-2026-10523EPSS 52%
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at…
Standalone Sentry
10.5.2 / 10.6.2+
CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…
Standalone Sentry
10.5.2 / 10.6.2+
CRITICAL 9.8
CVE-2026-7486
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio…
Mitigation only
CRITICAL 9.8
CVE-2026-46325
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
The current …
Linux Kernel
6.18.14 / 6.19.4+
CRITICAL 9.3
CVE-2026-46316
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased e…
Linux Kernel
6.12.93 / 6.18.35+
CRITICAL 9.8
CVE-2017-20251
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitra…
Mitigation only
CRITICAL 9.8
CVE-2026-46749
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation …
Sinec Ins
after 1.0
CRITICAL 9.3
CVE-2026-10731
SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-…
Mitigation only
CRITICAL 9.1
CVE-2025-10263
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte…
Mitigation only
CRITICAL 9.1
CVE-2009-10007
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.
Catalyst::Plugin::Authentication does…
Patch available
CRITICAL 9.8
CVE-2026-9698
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleEr…
Dbi
1.648+
CRITICAL 9.8
CVE-2026-44083
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln…
Qumagie
2.9.0+
CRITICAL 9.8
CVE-2026-5067
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Ke…
Zephyr
after 4.3.0
CRITICAL 9.8
CVE-2026-41855
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.conver…
Spring Framework
5.3.49 / 6.1.28+
CRITICAL 9.9
CVE-2026-44748
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …
Mitigation only
CRITICAL 9.0
CVE-2026-40128
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates fil…
Mitigation only
CRITICAL 9.8
CVE-2026-27671
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated …
Mitigation only
CRITICAL 9.6
CVE-2026-11697
Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox …
Chrome
149.0.7827.103+
CRITICAL 9.6
CVE-2026-11671
Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted…
Chrome
149.0.7827.103+