Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.6
CVE-2026-11659
Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a craf…
Chrome
149.0.7827.103+
CRITICAL 9.6
CVE-2026-11654
Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via…
Chrome
149.0.7827.103+
CRITICAL 9.6
CVE-2026-11651
Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…
Chrome
149.0.7827.103+
CRITICAL 9.6
CVE-2026-11638
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…
Chrome
149.0.7827.103+
CRITICAL 9.6
CVE-2026-11634
Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a…
Chrome
149.0.7827.103+
CRITICAL 9.8
CVE-2026-52778
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcFie…
Patch available
CRITICAL 9.0
CVE-2026-11393
Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote …
Mitigation only
CRITICAL 9.8
CVE-2026-46289
In the Linux kernel, the following vulnerability has been resolved:
lib/scatterlist: fix length calculations in extract_kvec_to_sg
Patch series "Fi…
Linux Kernel
6.6.140 / 6.12.88+
CRITICAL 9.4
CVE-2026-41448
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full…
Mitigation only
CRITICAL 9.8
CVE-2026-25555
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticate…
Mitigation only
CRITICAL 9.9
CVE-2026-46442EPSS 36%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function la…
Flowise
3.1.2+
CRITICAL 9.6
CVE-2026-46441
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…
Flowise
3.1.2+
CRITICAL 9.1
CVE-2026-46440
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate…
Flowise
3.1.2+
CRITICAL 9.8
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: fr…
HTTP Server
2.4.68+
CRITICAL 9.6
CVE-2026-42861
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…
Flowise
3.1.2+
CRITICAL 9.1
CVE-2026-42535
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…
HTTP Server
2.4.68+
CRITICAL 9.8
CVE-2026-29167
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 th…
HTTP Server
2.4.68+
CRITICAL 9.3
CVE-2026-50751 KEVEPSS 84%
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att…
Gaia Os
Patch available
CRITICAL 9.8
CVE-2026-11499EPSS 7%
A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK…
Mitigation only
CRITICAL 9.8
CVE-2024-58349
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by …
Mitigation only
CRITICAL 9.8
CVE-2024-58348
WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitra…
Mitigation only
CRITICAL 9.8
CVE-2023-54352
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading ma…
Mitigation only
CRITICAL 10.0
CVE-2026-11429
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi…
Mitigation only
CRITICAL 9.4
CVE-2026-11423
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in th…
Mitigation only
CRITICAL 9.8
CVE-2026-45779
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3…
Open Xdmod
10.0.3+
CRITICAL 9.8
CVE-2026-45777
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot…
Open Xdmod
11.0.3+
CRITICAL 9.6
CVE-2026-45758
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malic…
Guardrails Ai
Mitigation only
CRITICAL 9.8
CVE-2026-11420
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to…
On Prem Enterprise Server
8.1.1+
CRITICAL 9.8
CVE-2026-11414
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…
On Prem Enterprise Server
8.1.1+
CRITICAL 9.3
CVE-2026-46496
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26…
Mitigation only