Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-9406
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the…
Mitigation only
CRITICAL 9.8
CVE-2026-9405
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.c…
Mitigation only
CRITICAL 9.8
CVE-2026-9404
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the …
Mitigation only
CRITICAL 9.8
CVE-2026-9388
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cste…
Mitigation only
CRITICAL 9.8
CVE-2026-9387
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/c…
Mitigation only
CRITICAL 9.8
CVE-2026-9386
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of t…
Mitigation only
CRITICAL 9.8
CVE-2026-9385
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi…
Mitigation only
CRITICAL 9.8
CVE-2026-9384
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstec…
Mitigation only
CRITICAL 9.8
CVE-2018-25357
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…
Dolibarr Erp\/crm
after 7.0.3
CRITICAL 9.8
CVE-2018-25350
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requ…
Mitigation only
CRITICAL 9.8
CVE-2026-47280
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
Azure Resource Manager
No fix yet
CRITICAL 10.0
CVE-2026-42901
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Entra Id
Mitigation only
CRITICAL 9.3
CVE-2026-41090
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-40412
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
Azure Orbital Spatio
Mitigation only
CRITICAL 9.8
CVE-2026-33843
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privilege…
Entra Id
Mitigation only
CRITICAL 9.8
CVE-2026-23652
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…
Power Pages
Mitigation only
CRITICAL 9.3
CVE-2026-48700
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileMa…
Mitigation only
CRITICAL 10.0
CVE-2026-33712
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo…
Mitigation only
CRITICAL 9.8
CVE-2026-32253
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…
Sunshine
2026.516.143833+
CRITICAL 9.6
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl…
Net
0.55.0+
CRITICAL 9.1
CVE-2026-8673
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.
This issue affects Avan…
Avantra
25.3.0+
CRITICAL 9.6
CVE-2026-8670
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).
This…
Avantra
25.3.1+
CRITICAL 9.8
CVE-2026-44930
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…
Cxf
3.6.11 / 4.1.6+
CRITICAL 9.2
CVE-2026-9054
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.
Mitigation only
CRITICAL 10.0
CVE-2026-46595
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pu…
Crypto
0.52.0+
CRITICAL 9.1
CVE-2026-42508EPSS 7%
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check…
Crypto
0.52.0+
CRITICAL 9.1
CVE-2026-39834
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the w…
Crypto
0.52.0+
CRITICAL 9.1
CVE-2026-39833
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign …
Crypto
0.52.0+
CRITICAL 9.1
CVE-2026-39831
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence …
Crypto
0.52.0+
CRITICAL 9.1
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio…
Crypto
0.52.0+