Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.9
CVE-2026-9559
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw …
Mitigation only
CRITICAL 9.8
CVE-2025-41277
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41276
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41275
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41274
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41273
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and R…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41272
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41270
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.8
CVE-2025-41269
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.1
CVE-2025-41268
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 …
Wf 500 Firmware
after 7.9.1.0_r2502171040
CRITICAL 9.9
CVE-2026-9558
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox…
Mitigation only
CRITICAL 9.8
CVE-2026-49201
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify…
Wave 7 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49200
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentia…
Wave 7 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49199
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
Predator Connect W6x Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-49197
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai…
Predator Connect W6x Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-3655
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This…
Mitigation only
CRITICAL 9.8
CVE-2026-8732EPSS 22%
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6…
Mitigation only
CRITICAL 9.6
CVE-2026-9967
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…
Chrome
148.0.7778.215 / 148.0.7778.216+
CRITICAL 9.6
CVE-2026-9918
Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a…
Chrome
148.0.7778.216+
CRITICAL 9.0
CVE-2026-9891
Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potential…
Chrome
148.0.7778.215 / 148.0.7778.216+
CRITICAL 9.6
CVE-2026-9886
Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafte…
Chrome
148.0.7778.216+
CRITICAL 9.0
CVE-2026-9881
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension…
Chrome
148.0.7778.216+
CRITICAL 9.6
CVE-2026-9876
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a c…
Chrome
148.0.7778.216+
CRITICAL 9.6
CVE-2026-9875
Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via…
Chrome
148.0.7778.216+
CRITICAL 9.6
CVE-2026-9874
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
148.0.7778.215 / 148.0.7778.216+
CRITICAL 9.6
CVE-2026-9872
Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via …
Chrome
148.0.7778.216+
CRITICAL 9.8
CVE-2026-8809
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu…
Mitigation only
CRITICAL 9.9
CVE-2026-44881
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…
Portainer
2.33.8 / 2.39.2+
CRITICAL 9.9
CVE-2026-9645
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli…
Scadabr
Mitigation only
CRITICAL 10.0
CVE-2026-46840
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit…
Rest Data Services
after 26.1.0