Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-5722
The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the gues…
Mitigation only
CRITICAL 9.8
CVE-2026-42238
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) tha…
Nginx Ui
2.3.8+
CRITICAL 9.8
CVE-2026-42222
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init…
Nginx Ui
Mitigation only
CRITICAL 9.8
CVE-2026-42221
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim …
Nginx Ui
2.3.8+
CRITICAL 9.3
CVE-2026-41926
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request …
Mitigation only
CRITICAL 9.3
CVE-2026-41925
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function th…
Mitigation only
CRITICAL 9.3
CVE-2026-41924
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unaut…
Mitigation only
CRITICAL 9.3
CVE-2026-41923
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthen…
Mitigation only
CRITICAL 9.3
CVE-2026-41922
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthen…
Mitigation only
CRITICAL 9.6
CVE-2026-42235
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a mali…
N8n
1.123.32 / 2.17.4+
CRITICAL 9.8
CVE-2026-42233
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select opera…
N8n
1.123.32 / 2.17.4+
CRITICAL 9.8
CVE-2026-42796
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que…
Arelle
2.39.10+
CRITICAL 9.6
CVE-2026-42087
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before …
Cosmos
7.0.0+
CRITICAL 9.4
CVE-2026-41571
Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("nu…
Mitigation only
CRITICAL 9.9
CVE-2026-42812
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to re…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42811
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or tabl…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42810
Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds temporary S3 access policies for delegated table acc…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42809
Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been val…
Polaris
1.4.1+
CRITICAL 9.8
CVE-2026-42376
D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init…
Dir 456u Firmware
Mitigation only
CRITICAL 9.6
CVE-2026-42090
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi…
Notesnook Desktop
3.3.15 / 3.3.20+
CRITICAL 9.8
CVE-2026-42076
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function…
Mitigation only
CRITICAL 9.8
CVE-2026-42027
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…
Opennlp
2.5.9+
CRITICAL 9.1
CVE-2026-40682
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0…
Opennlp
2.5.9+
CRITICAL 9.8
CVE-2026-26956
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker cod…
Vm2
3.10.5+
CRITICAL 10.0
CVE-2026-26332
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.…
Vm2
3.11.0+
CRITICAL 9.8
CVE-2026-25293
Buffer overflow due to incorrect authorization in PLC FW
Qca7005 Firmware
No fix yet
CRITICAL 9.8
CVE-2026-24120
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing at…
Vm2
3.10.5+
CRITICAL 9.8
CVE-2026-24118
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr…
Vm2
3.11.0+
CRITICAL 9.8
CVE-2026-24781
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function…
Vm2
3.11.0+
CRITICAL 9.3
CVE-2025-13605
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands …
Mitigation only