Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 9.8
CVE-2026-6886
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remo…
Mitigation only
CRITICAL 9.8
CVE-2026-6885
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated rem…
Mitigation only
CRITICAL 9.8
CVE-2026-3960
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior…
H2o
3.46.0.10+
CRITICAL 9.1
CVE-2026-41229
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo…
Froxlor
2.3.6+
CRITICAL 9.9
CVE-2026-41228
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does…
Froxlor
2.3.6+
CRITICAL 9.8
CVE-2026-3844EPSS 28%
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'…
Mitigation only
CRITICAL 10.0
CVE-2026-41679
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…
Paperclipai
2026.416.0+
CRITICAL 10.0
CVE-2026-41211
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` …
Vite\+
0.1.17+
CRITICAL 9.3
CVE-2026-41197
Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode …
Mitigation only
CRITICAL 10.0
CVE-2026-41196
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can…
Minetest
5.15.2+
CRITICAL 9.8
CVE-2026-5935
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…
Total Storage Service Console
Mitigation only
CRITICAL 9.8
CVE-2026-41179EPSS 9%
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…
Rclone
1.73.5+
CRITICAL 9.8
CVE-2026-41176EPSS 33%
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose…
Rclone
1.73.5+
CRITICAL 9.8
CVE-2026-29198
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o…
Rocket.chat
7.10.9 / 7.11.6+
CRITICAL 9.1
CVE-2026-41167
Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by in…
Patch available
CRITICAL 9.1
CVE-2026-33656
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …
Espocrm
9.3.4+
CRITICAL 9.6
CVE-2026-33471
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len…
Nimiq Proof Of Stake
1.3.0+
CRITICAL 9.8
CVE-2026-34415
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to…
Patch available
CRITICAL 9.8
CVE-2026-26354
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.60+
CRITICAL 9.1
CVE-2026-32885
DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction …
Ddev
1.25.2+
CRITICAL 9.8
CVE-2018-25272
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with S…
Mitigation only
CRITICAL 9.8
CVE-2018-25270
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functi…
Thinkphp
5.0.23+
CRITICAL 9.6
CVE-2026-6356
A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipul…
Augmentt
2025-10-02+
CRITICAL 9.8
CVE-2026-33608
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…
Authoritative
4.9.14 / 5.0.4+
CRITICAL 9.1
CVE-2026-33598
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c…
Dnsdist
1.9.13 / 2.0.4+
CRITICAL 9.8
CVE-2026-31501
In the Linux kernel, the following vulnerability has been resolved:
net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path
cppi5_h…
Linux Kernel
6.19.11+
CRITICAL 9.8
CVE-2026-31478
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()…
Linux Kernel
5.15.203 / 6.1.168+
CRITICAL 9.8
CVE-2026-31463
In the Linux kernel, the following vulnerability has been resolved:
iomap: fix invalid folio access when i_blkbits differs from I/O granularity
Com…
Linux Kernel
6.19.11+
CRITICAL 9.4
CVE-2026-31448
In the Linux kernel, the following vulnerability has been resolved:
ext4: avoid infinite loops caused by residual data
On the mkdir/mknod path, whe…
Linux Kernel
6.1.168 / 6.6.131+
CRITICAL 9.8
CVE-2026-31444
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
smb_grant_oplock…
Linux Kernel
6.12.80 / 6.18.21+