Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 10.0
CVE-2026-35431
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
Entra Id
Mitigation only
CRITICAL 9.8
CVE-2026-33819
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Bing
Mitigation only
CRITICAL 9.3
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-26210
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a…
Ktransformers
after 0.5.3
CRITICAL 10.0
CVE-2026-26150
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview Ediscovery
Mitigation only
CRITICAL 9.6
CVE-2026-24303
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Partner Center
No fix yet
CRITICAL 9.8
CVE-2026-41276EPSS 7%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41268EPSS 14%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41267
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41265
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-41264
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…
Flowise
3.1.0+
CRITICAL 9.8
CVE-2026-25874EPSS 16%
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da…
Lerobot
after 0.5.1
CRITICAL 9.8
CVE-2026-6074
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debu…
Mitigation only
CRITICAL 9.8
CVE-2026-41247
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner…
Elfinder
2.1.67+
CRITICAL 9.6
CVE-2026-6920
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to p…
Chrome
147.0.7727.116+
CRITICAL 9.6
CVE-2026-6919
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially…
Chrome
147.0.7727.116+
CRITICAL 9.8
CVE-2026-31533
In the Linux kernel, the following vulnerability has been resolved:
net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
The -EBUS…
Linux Kernel
5.15.203 / 6.1.169+
CRITICAL 9.8
CVE-2026-31181
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…
A3300r Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-31178
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…
A3300r Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-31177
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…
A3300r Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-31175
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…
A3300r Firmware
Mitigation only
CRITICAL 9.9
CVE-2026-40472
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cro…
Mitigation only
CRITICAL 9.6
CVE-2026-40471
hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage s…
Mitigation only
CRITICAL 9.9
CVE-2026-40470
A critical XSS vulnerability affected hackage-server and
hackage.haskell.org. HTML and JavaScript files provided in source
packages or via the docum…
Mitigation only
CRITICAL 9.8
CVE-2026-23751
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel …
Mitigation only
CRITICAL 9.8
CVE-2025-62373
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a v…
Pipecat
0.0.94+
CRITICAL 9.8
CVE-2025-50229
Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
Jizhicms
Mitigation only
CRITICAL 9.8
CVE-2026-41460
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input p…
Socialengine
after 7.8.0
CRITICAL 9.9
CVE-2026-39440
Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue aff…
Mitigation only
CRITICAL 9.8
CVE-2026-6887
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attac…
Mitigation only