Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked gor…
Crypto
0.52.0+
CRITICAL 9.3
CVE-2026-9264
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr…
Mitigation only
CRITICAL 10.0
CVE-2026-34910 KEVEPSS 87%
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command …
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 9.1
CVE-2026-33000
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices t…
Unifi Os Server
5.0.8+
CRITICAL 9.8
CVE-2026-6960
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_s…
Mitigation only
CRITICAL 9.8
CVE-2026-48207
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…
Fory
1.0.0+
CRITICAL 9.3
CVE-2026-39531
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind …
Mitigation only
CRITICAL 9.8
CVE-2025-71211
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…
Apex One
14.0.0.14136 / 14.0.20315+
CRITICAL 9.8
CVE-2025-71210
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…
Apex One
14.0.0.14136 / 14.0.20315+
CRITICAL 9.8
CVE-2026-5118
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin a…
Mitigation only
CRITICAL 9.8
CVE-2026-43501
In the Linux kernel, the following vulnerability has been resolved:
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
ipv6_rpl_srh_rc…
Linux Kernel
5.10.258 / 5.15.209+
CRITICAL 9.1
CVE-2026-5433
Honeywell Control
Network Module (CNM) contains command injection vulnerability
in the web interface. An attacker could exploit this vulnerability vi…
No fix yet
CRITICAL 9.9
CVE-2026-4858
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …
Mattermost Server
10.11.15 / 11.4.5+
CRITICAL 9.9
CVE-2026-44050
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute…
Mitigation only
CRITICAL 9.8
CVE-2026-6279
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions…
Mitigation only
CRITICAL 10.0
CVE-2026-9152
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri…
Mitigation only
CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…
Litespeed Cpanel Plugin
2.4.7 / 5.3.1.0+
CRITICAL 9.1
CVE-2026-47372
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is …
Patch available
CRITICAL 9.8
CVE-2026-8631
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati…
Linux Imaging And Printing
3.26.4+
CRITICAL 9.8
CVE-2026-9141
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that…
Mitigation only
CRITICAL 9.8
CVE-2026-9139
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where…
Mitigation only
CRITICAL 9.4
CVE-2026-9129
A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters…
Mitigation only
CRITICAL 9.4
CVE-2026-9102
A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa…
Mitigation only
CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This …
Drupal
10.4.10 / 10.5.10+
CRITICAL 10.0
CVE-2026-45444
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.
This issue a…
Mitigation only
CRITICAL 9.4
CVE-2026-39405
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with cour…
Mitigation only
CRITICAL 9.3
CVE-2026-33137
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. I…
Patch available
CRITICAL 9.3
CVE-2026-23734EPSS 20%
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by u…
Patch available