Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-31607
In the Linux kernel, the following vulnerability has been resolved:
usbip: validate number_of_packets in usbip_pack_ret_submit()
When a USB/IP clie…
Linux Kernel
6.6.136 / 6.12.83+
CRITICAL 9.8
CVE-2026-31589
In the Linux kernel, the following vulnerability has been resolved:
mm: call ->free_folio() directly in folio_unmap_invalidate()
We can only call f…
Linux Kernel
6.19.14 / 7.0.1+
CRITICAL 9.8
CVE-2026-31536
In the Linux kernel, the following vulnerability has been resolved:
smb: server: let send_done handle a completion without IB_SEND_SIGNALED
With sm…
Linux Kernel
6.18.11 / 6.19.1+
CRITICAL 9.8
CVE-2026-25660
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs …
Codechecker
6.27.4+
CRITICAL 9.9
CVE-2026-21515
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
Azure Iot Central
No fix yet
CRITICAL 9.8
CVE-2026-1951
Delta Electronics AS320T has no checking of the length of the buffer with the directory name
vulnerability.
As320t Firmware
1.12+
CRITICAL 9.8
CVE-2026-1950
Delta Electronics AS320T has
No checking of the length of the buffer with the file name vulnerability.
As320t Firmware
1.16+
CRITICAL 9.8
CVE-2026-1949
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.
As320t Firmware
1.16+
CRITICAL 9.1
CVE-2026-41323
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…
Kyverno
1.16.4 / 1.17.2+
CRITICAL 9.8
CVE-2026-33078
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…
Roxy Wi
8.2.6.4+
CRITICAL 9.8
CVE-2026-33076
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…
Roxy Wi
8.2.6.4+
CRITICAL 9.8
CVE-2026-40630
A vulnerability in
SenseLive
X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access…
X3500 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-40620
A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat…
X3500 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-35503
A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har…
X3500 Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-27843
A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient …
X3500 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-25775
A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication…
Mitigation only
CRITICAL 9.8
CVE-2026-41274
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-pr…
Flowise
3.1.0+
CRITICAL 10.0
CVE-2026-35431
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
Entra Id
Mitigation only
CRITICAL 9.8
CVE-2026-33819
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Bing
Mitigation only
CRITICAL 9.3
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-26210
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a…
Ktransformers
after 0.5.3
CRITICAL 10.0
CVE-2026-26150
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview Ediscovery
Mitigation only
CRITICAL 9.6
CVE-2026-24303
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Partner Center
No fix yet
CRITICAL 9.8
CVE-2026-41276EPSS 7%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41268EPSS 14%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41267
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41265
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41264
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-25874EPSS 16%
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da…
Lerobot
after 0.5.1
CRITICAL 9.8
CVE-2026-6074
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debu…
Mitigation only