Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.6
CVE-2026-5166
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institu…
Mitigation only
CRITICAL 9.8
CVE-2026-41940 KEVEPSS 99%
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …
Wp Squared
86.0.41 / 110.0.97+
CRITICAL 9.8
CVE-2026-38992
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows a…
Mitigation only
CRITICAL 9.8
CVE-2026-36841
TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.
Mitigation only
CRITICAL 9.0
CVE-2026-42523
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHu…
GitHub
1.46.0.1+
CRITICAL 9.8
CVE-2026-42249
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…
Ollama
after 0.17.5
CRITICAL 9.8
CVE-2026-42248
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl…
Ollama
after 0.17.5
CRITICAL 10.0
CVE-2026-3325
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The v…
Mitigation only
CRITICAL 9.6
CVE-2026-7333
Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…
Chrome
147.0.7727.138+
CRITICAL 9.8
CVE-2026-41446
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MA…
Mitigation only
CRITICAL 9.6
CVE-2026-41397
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du…
Openclaw
2026.3.31+
CRITICAL 9.8
CVE-2026-41386
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes…
Openclaw
2026.3.22+
CRITICAL 9.4
CVE-2026-3893
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism,
allowing an attacker with network access to directly access and modify
its con…
Mitigation only
CRITICAL 9.8
CVE-2026-24178
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause author…
Nvflare
2.7.2+
CRITICAL 9.8
CVE-2026-41873
** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…
Pony Mail
Mitigation only
CRITICAL 9.8
CVE-2025-60889
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or othe…
Hpx
after 1.11.0
CRITICAL 9.6
CVE-2026-7321
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150…
Firefox
140.10.1 / 150.0+
CRITICAL 9.4
CVE-2026-7248
A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. Th…
Di 8100 Firmware
No fix yet
CRITICAL 9.8
CVE-2026-7244
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cg…
Mitigation only
CRITICAL 9.8
CVE-2026-7243
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi…
Mitigation only
CRITICAL 9.8
CVE-2026-7242
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi…
Mitigation only
CRITICAL 9.8
CVE-2026-7241
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi o…
Mitigation only
CRITICAL 9.8
CVE-2026-7240
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin…
Mitigation only
CRITICAL 9.8
CVE-2026-7204
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi…
Mitigation only
CRITICAL 9.8
CVE-2026-7203
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cst…
Mitigation only
CRITICAL 9.8
CVE-2026-7202
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of…
Mitigation only
CRITICAL 9.8
CVE-2026-32644
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Mitigation only
CRITICAL 9.1
CVE-2026-40976
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v…
Spring Boot
4.0.6+
CRITICAL 9.8
CVE-2026-40974
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring…
Spring Boot
2.7.33 / 3.3.19+
CRITICAL 9.1
CVE-2026-40971
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM…
Spring Boot
3.5.14 / 4.0.6+