Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 10.0
CVE-2026-20223
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…
Secure Workload
3.10.8.3 / 4.0.3.17+
CRITICAL 9.1
CVE-2026-8598
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
expose…
Mitigation only
CRITICAL 9.5
CVE-2026-8467
Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol…
Patch available
CRITICAL 9.9
CVE-2026-24425
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with te…
Twig
3.26.0+
CRITICAL 9.8
CVE-2026-3593
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr…
Bind
9.20.23 / 9.21.22+
CRITICAL 9.8
CVE-2025-31973
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images …
Bigfix Service Management
Mitigation only
CRITICAL 9.0
CVE-2026-22314
Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en…
Mitigation only
CRITICAL 10.0
CVE-2026-42960
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSet…
Unbound
1.25.1+
CRITICAL 9.8
CVE-2026-33278
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible …
Unbound
1.25.1+
CRITICAL 9.3
CVE-2026-9065
SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'p…
Mitigation only
CRITICAL 9.3
CVE-2026-9059
NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/…
Mitigation only
CRITICAL 9.8
CVE-2026-7637
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input i…
Mitigation only
CRITICAL 9.8
CVE-2026-24214
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit o…
Triton Inference Server
26.03+
CRITICAL 9.8
CVE-2026-24213
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit…
Triton Inference Server
26.03+
CRITICAL 9.8
CVE-2026-24207
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab…
Triton Inference Server
26.03+
CRITICAL 9.8
CVE-2026-24206
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab…
Triton Inference Server
26.03+
CRITICAL 9.8
CVE-2026-24163
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful explo…
Tensorrt Llm
1.2+
CRITICAL 9.8
CVE-2026-24142
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability m…
Tensorrt Llm
1.2+
CRITICAL 9.8
CVE-2025-33255
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit…
Tensorrt Llm
1.2+
CRITICAL 9.8
CVE-2026-7284
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all …
Mitigation only
CRITICAL 9.8
CVE-2026-6555
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an arra…
Mitigation only
CRITICAL 9.8
CVE-2026-8495
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.
This issue affects Date iCal: from 0.0.0 before 4.0.15.
Date Ical
4.0.15+
CRITICAL 10.0
CVE-2026-34234
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is…
Mitigation only
CRITICAL 9.8
CVE-2026-33642
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds…
Kitty
0.47.0+
CRITICAL 9.8
CVE-2026-8605
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
Scadabr
Mitigation only
CRITICAL 9.8
CVE-2026-8603
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
Scadabr
Mitigation only
CRITICAL 9.1
CVE-2026-8602
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req…
Scadabr
Mitigation only
CRITICAL 9.8
CVE-2026-36829
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…
Mitigation only
CRITICAL 9.8
CVE-2026-37281
An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbit…
Patch available
CRITICAL 9.8
CVE-2026-31072
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via In…
Mitigation only