Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-50225
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-50214
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost networ…
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-50211
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to int…
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.4
CVE-2026-50208
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Mi…
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49191
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49188
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execu…
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49186
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +…
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49185
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
Connect M6e 5g Firmware
Mitigation only
CRITICAL 9.9
CVE-2026-41283
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which…
Mitigation only
CRITICAL 9.1
CVE-2026-46266
In the Linux kernel, the following vulnerability has been resolved:
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Yizhou Zhao reporte…
Linux Kernel
6.6.128 / 6.12.75+
CRITICAL 9.1
CVE-2026-46244
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), wh…
Linux Kernel
6.6.142 / 6.12.92+
CRITICAL 9.0
CVE-2026-36748
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
Mitigation only
CRITICAL 9.8
CVE-2026-36576
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb…
Mitigation only
CRITICAL 9.6
CVE-2026-5241
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu…
Transformers
Patch available
CRITICAL 9.8
CVE-2026-35075
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Universal Gateway Firmware
6_00_07+
CRITICAL 9.8
CVE-2026-47065
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the seri…
Mina
Mitigation only
CRITICAL 9.9
CVE-2025-14771
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
T Mac Plus
Mitigation only
CRITICAL 9.1
CVE-2026-35482
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca…
Alf
2.0-M5-2606+
CRITICAL 9.6
CVE-2026-32625
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s…
Librechat
0.8.4+
CRITICAL 9.8
CVE-2026-49448
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em…
Authentik
2025.12.6 / 2026.2.4+
CRITICAL 9.3
CVE-2026-42849
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow …
Authentik
2025.12.5 / 2026.2.3+
CRITICAL 9.8
CVE-2026-5076
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plug…
Mitigation only
CRITICAL 9.8
CVE-2026-38967
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
Patch available
CRITICAL 9.8
CVE-2026-42074
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableS…
Openclaude
0.5.1+
CRITICAL 9.8
CVE-2026-0611
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability thro…
Mitigation only
CRITICAL 9.8
CVE-2026-47117
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used …
Patch available
CRITICAL 9.8
CVE-2026-7198
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access…
Sitefinity
15.4.8630+
CRITICAL 10.0
CVE-2026-10611
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with …
Misp
2.5.39+
CRITICAL 9.3
CVE-2026-42684
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.…
Mitigation only
CRITICAL 9.3
CVE-2026-34906
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoin…
Mitigation only