Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.9
CVE-2026-46839
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili…
Rest Data Services
after 26.1.0
CRITICAL 9.0
CVE-2026-46833
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit …
Database Server
after 23.26.2
CRITICAL 9.9
CVE-2026-46824
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported …
Universal Work Queue
after 12.2.15
CRITICAL 9.9
CVE-2026-46822
Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…
Iassets
after 12.2.15
CRITICAL 9.1
CVE-2026-46819
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions t…
E Business Suite
after 12.2.15
CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…
E Business Suite
after 12.2.15
CRITICAL 9.9
CVE-2026-46775
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili…
Rest Data Services
after 26.1.0
CRITICAL 9.8
CVE-2026-45288
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-suppl…
Patch available
CRITICAL 9.8
CVE-2026-34311
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions …
Hospitality Opera 5 Property Services
Mitigation only
CRITICAL 9.3
CVE-2026-9037
A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device'…
Mitigation only
CRITICAL 9.8
CVE-2026-45039
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-…
Mitigation only
CRITICAL 9.1
CVE-2026-45787
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero…
Electerm
3.9.5+
CRITICAL 9.6
CVE-2026-45374
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure de…
Mitigation only
CRITICAL 9.6
CVE-2026-45323
MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-…
Meshcore Card
0.3.3+
CRITICAL 9.6
CVE-2026-45311
CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalR…
Mitigation only
CRITICAL 9.4
CVE-2026-45058
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code ex…
Mitigation only
CRITICAL 10.0
CVE-2026-43898
SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover th…
Sandboxjs
0.9.6+
CRITICAL 9.1
CVE-2026-9098
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs witho…
Mitigation only
CRITICAL 9.8
CVE-2026-9097
Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object…
Mitigation only
CRITICAL 9.8
CVE-2026-9094
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object…
Mitigation only
CRITICAL 9.8
CVE-2026-9093
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertion…
Mitigation only
CRITICAL 9.1
CVE-2026-9092
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByB…
Mitigation only
CRITICAL 9.1
CVE-2026-9090
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certi…
Mitigation only
CRITICAL 9.3
CVE-2026-45261
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in t…
Mitigation only
CRITICAL 9.9
CVE-2026-44477
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG met…
Cloudnativepg
1.28.3 / 1.29.1+
CRITICAL 9.8
CVE-2026-38707
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware…
Ir315 Firmware
1.0.121 / 3.5.112+
CRITICAL 9.8
CVE-2026-38704
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firm…
Ir315 Firmware
1.0.121 / 3.5.112+
CRITICAL 9.8
CVE-2026-38703
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…
Ir315 Firmware
1.0.121 / 3.5.112+
CRITICAL 9.8
CVE-2026-38702
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…
Ir315 Firmware
1.0.121 / 3.5.112+
CRITICAL 9.8
CVE-2026-24444
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfa…
Mitigation only