Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-31071
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit…
Mitigation only
CRITICAL 9.8
CVE-2026-31070
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an admin…
Mitigation only
CRITICAL 9.8
CVE-2026-30118
scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. T…
Mitigation only
CRITICAL 9.8
CVE-2026-30117
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpo…
Mitigation only
CRITICAL 9.8
CVE-2026-8711EPSS 10%
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,…
Njs
0.9.9+
CRITICAL 9.8
CVE-2026-44159
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment.…
Mitigation only
CRITICAL 9.6
CVE-2026-2587
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget hand…
Glassfish
8.0.2+
CRITICAL 9.1
CVE-2026-2586
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can …
Glassfish
8.0.2+
CRITICAL 9.6
CVE-2026-8959
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, …
Firefox
140.11 / 140.11.0+
CRITICAL 9.8
CVE-2026-8956
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird …
Firefox
140.11 / 140.11.0+
CRITICAL 9.6
CVE-2026-8953
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefo…
Firefox
115.36.0 / 140.11+
CRITICAL 9.3
CVE-2026-8950
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Th…
Firefox
140.11 / 140.11.0+
CRITICAL 9.1
CVE-2026-8948
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Firefox
151.0.0+
CRITICAL 9.8
CVE-2026-47323
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe…
Camel
4.14.6 / 4.18.2+
CRITICAL 10.0
CVE-2026-43633
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch betwe…
Patch available
CRITICAL 9.8
CVE-2026-4883
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_buil…
Mitigation only
CRITICAL 9.8
CVE-2026-43493
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix handling of MAY_BACKLOG requests
MAY_BACKLOG requests can …
Linux Kernel
5.10.258 / 5.15.209+
CRITICAL 9.2
CVE-2026-46725
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated att…
Mitigation only
CRITICAL 9.8
CVE-2026-45434EPSS 22%
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBi…
Ofbiz
24.09.06+
CRITICAL 9.1
CVE-2026-41919
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz:…
Ofbiz
24.09.06+
CRITICAL 9.1
CVE-2026-31986
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgra…
Ofbiz
24.09.06+
CRITICAL 9.6
CVE-2026-2611
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a r…
Mlflow
3.10.0+
CRITICAL 9.8
CVE-2026-4885
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_aja…
Mitigation only
CRITICAL 9.8
CVE-2026-47314
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce…
Escargot
Patch available
CRITICAL 9.8
CVE-2026-47311
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da85…
Escargot
Patch available
CRITICAL 9.8
CVE-2026-47310
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6…
Escargot
Patch available
CRITICAL 9.8
CVE-2026-8838
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue serve…
Mitigation only
CRITICAL 9.9
CVE-2026-27130
Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 c…
Patch available
CRITICAL 9.8
CVE-2026-25244
WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 cont…
Webdriverio
9.24.0+
CRITICAL 9.8
CVE-2026-8836
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the componen…
Patch available