Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-44277
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…
Fortiauthenticator
6.5.7 / 6.6.9+
CRITICAL 9.1
CVE-2026-44196
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows …
Mitigation only
CRITICAL 9.8
CVE-2026-44183
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Pri…
Mitigation only
CRITICAL 9.9
CVE-2026-42898
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
CRITICAL 9.1
CVE-2026-42833
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
CRITICAL 9.3
CVE-2026-42300
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admi…
Patch available
CRITICAL 9.6
CVE-2026-42048
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…
Langflow
1.9.0+
CRITICAL 9.1
CVE-2026-41103EPSS 5%
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri…
Confluence Saml Sso
1.3.3 / 7.4.0+
CRITICAL 9.8
CVE-2026-41096
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.22631.7079 / 10.0.25398.2330+
CRITICAL 9.8
CVE-2026-41089EPSS 80%
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.9140 / 10.0.17763.8755+
CRITICAL 9.3
CVE-2026-40402
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.5074 / 10.0.22631.7079+
CRITICAL 9.9
CVE-2026-33821
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Customer Insights
Mitigation only
CRITICAL 9.1
CVE-2026-33117
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…
Azure Sdk For Java
4.10.6+
CRITICAL 9.1
CVE-2026-31242
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin…
Mem0
Mitigation only
CRITICAL 9.8
CVE-2026-31239
The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hu…
Mitigation only
CRITICAL 9.8
CVE-2026-31238
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server wit…
Mitigation only
CRITICAL 9.8
CVE-2026-31237
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset fil…
Mitigation only
CRITICAL 9.8
CVE-2026-31236
The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to…
Mitigation only
CRITICAL 9.8
CVE-2026-31235
The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The…
Mitigation only
CRITICAL 9.8
CVE-2026-31234
Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for d…
Mitigation only
CRITICAL 9.8
CVE-2026-31233
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packag…
Mitigation only
CRITICAL 9.8
CVE-2026-31231
Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to e…
Mitigation only
CRITICAL 9.8
CVE-2026-31230
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_e…
Mitigation only
CRITICAL 9.8
CVE-2026-31229
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model l…
Mitigation only
CRITICAL 9.1
CVE-2026-29204
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without a…
Mitigation only
CRITICAL 9.8
CVE-2026-26083
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…
Fortisandbox
4.4.9 / 5.0.2+
CRITICAL 9.8
CVE-2026-43992
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…
Patch available
CRITICAL 9.3
CVE-2026-20794
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an…
Mitigation only
CRITICAL 9.8
CVE-2025-65719
An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted H…
Mitigation only