Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 10.0
CVE-2026-35435
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.6
CVE-2026-35428
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…
Azure Cloud Shell
Mitigation only
CRITICAL 9.0
CVE-2026-33844
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.9
CVE-2026-33109
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.1
CVE-2026-41691
Copilot said: i18nextify is a JavaScript library that adds
i18nextify is a JavaScript library that adds website internationalization via a script tag…
I18next Http Backend
3.0.5+
CRITICAL 9.8
CVE-2026-42284
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list,…
Gitpython
3.1.47+
CRITICAL 9.1
CVE-2026-41902
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts …
Mitigation only
CRITICAL 9.8
CVE-2026-37709
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to …
Snipe It
8.4.1+
CRITICAL 9.8
CVE-2026-7415
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th…
Lawn Mower Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-7414
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all device…
Lawn Mower Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-7413
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged…
Lawn Mower Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-7821
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.8
CVE-2026-5788
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.1
CVE-2026-5787
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.8
CVE-2025-63704
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and…
Mitigation only
CRITICAL 9.8
CVE-2025-63703
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
Mitigation only
CRITICAL 9.8
CVE-2026-36458
ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injec…
Mitigation only
CRITICAL 9.8
CVE-2025-63706
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
Mitigation only
CRITICAL 9.6
CVE-2026-6795
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
…
Mitigation only
CRITICAL 9.6
CVE-2026-41589
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wis…
Wish
No fix yet
CRITICAL 9.8
CVE-2026-30496
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated …
Mitigation only
CRITICAL 9.8
CVE-2026-8094
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
Firefox
140.10.2+
CRITICAL 9.8
CVE-2026-8091
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.1…
Firefox
115.35.2 / 140.10.1+
CRITICAL 9.8
CVE-2026-6508
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Proper…
Mitigation only
CRITICAL 9.8
CVE-2026-42010
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…
Hardened Images
Mitigation only
CRITICAL 10.0
CVE-2026-33587
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the dock…
Open Notebook
1.8.4+
CRITICAL 9.8
CVE-2025-1978
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G3…
Virtual Storage One Block
Mitigation only
CRITICAL 9.8
CVE-2025-9661
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28.
This…
Virtual Storage One Block
Mitigation only
CRITICAL 9.3
CVE-2026-41586
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to…
Mitigation only
CRITICAL 9.1
CVE-2026-44603
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Tor
0.4.9.7+