Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.3
CVE-2026-44128
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes atta…
Mitigation only
CRITICAL 9.2
CVE-2026-44126
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow u…
Mitigation only
CRITICAL 9.3
CVE-2026-44125
SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthe…
Mitigation only
CRITICAL 9.8
CVE-2026-43341
In the Linux kernel, the following vulnerability has been resolved:
net/ipv6: ioam6: prevent schema length wraparound in trace fill
ioam6_fill_trac…
Linux Kernel
6.1.168 / 6.6.134+
CRITICAL 9.8
CVE-2026-43304
In the Linux kernel, the following vulnerability has been resolved:
libceph: define and enforce CEPH_MAX_KEY_LEN
When decoding the key, verify that…
Linux Kernel
5.15.202 / 6.1.165+
CRITICAL 9.9
CVE-2026-41512
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab…
0din Scanner
1.4.1+
CRITICAL 9.8
CVE-2026-41509
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there i…
Cross Implementation
2026-03-23+
CRITICAL 9.8
CVE-2026-41507
math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim i…
Math Codegen
0.4.3+
CRITICAL 9.8
CVE-2026-41497
PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg…
Praisonai
4.6.9+
CRITICAL 9.1
CVE-2026-25199
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudSt…
Cloudstack
4.22.0.1+
CRITICAL 9.8
CVE-2026-8153
OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft co…
Mitigation only
CRITICAL 9.3
CVE-2026-8076
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentic…
Mitigation only
CRITICAL 10.0
CVE-2026-6213
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code exec…
Mitigation only
CRITICAL 9.1
CVE-2013-10075
Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Sto…
Apache\
after 1.94
CRITICAL 9.9
CVE-2025-69691
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only …
Pfsense
Mitigation only
CRITICAL 9.1
CVE-2025-69690
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo…
Pfsense
No fix yet
CRITICAL 9.8
CVE-2025-69599
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: th…
Mitigation only
CRITICAL 9.8
CVE-2025-67887
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and exec…
Mitigation only
CRITICAL 9.8
CVE-2023-46453
Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both…
Mitigation only
CRITICAL 9.1
CVE-2024-51092EPSS 7%
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…
Librenms
24.10.0+
CRITICAL 9.6
CVE-2026-43944
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerabl…
Electerm
3.8.15+
CRITICAL 9.6
CVE-2026-43941
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink…
Electerm
after 3.8.15
CRITICAL 9.1
CVE-2026-42264
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL…
Axios
1.15.2+
CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…
Litellm
1.83.7+
CRITICAL 10.0
CVE-2026-41900
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was…
Openlearnx
Patch available
CRITICAL 9.8
CVE-2026-41501
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…
Electerm
3.3.8+
CRITICAL 9.8
CVE-2026-41500
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…
Electerm
3.3.8+
CRITICAL 9.6
CVE-2026-42880
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a …
Argo Cd
3.2.11 / 3.3.9+
CRITICAL 9.8
CVE-2026-8034
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access …
Enterprise Server
3.16.18 / 3.17.15+
CRITICAL 9.1
CVE-2026-7891
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special …
Mitigation only