Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 9.8
CVE-2026-31436
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()
…
Linux Kernel
6.12.80 / 6.18.21+
CRITICAL 9.8
CVE-2026-6235
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up …
Mitigation only
CRITICAL 9.1
CVE-2026-4119
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin…
Mitigation only
CRITICAL 9.8
CVE-2026-6023
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…
Telerik Ui For Asp.net Ajax
2026.1.421+
CRITICAL 9.8
CVE-2026-41304
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel…
Avideo
after 29.0
CRITICAL 9.8
CVE-2026-41144
F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, …
Fprime
Patch available
CRITICAL 9.3
CVE-2026-41064
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f…
Avideo
after 29.0
CRITICAL 9.1
CVE-2026-40575
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-For…
Oauth2 Proxy
7.15.2+
CRITICAL 9.6
CVE-2026-5845
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac…
Enterprise Server
3.14.26 / 3.15.21+
CRITICAL 9.2
CVE-2026-40946
Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in t…
Mitigation only
CRITICAL 9.9
CVE-2026-40933EPSS 13%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…
Flowise
3.1.0+
CRITICAL 10.0
CVE-2026-40911
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa…
Avideo
after 29.0
CRITICAL 9.1
CVE-2026-40910
frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used…
Frp
0.68.1+
CRITICAL 9.8
CVE-2026-40892
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_crea…
Pjsip
2.17+
CRITICAL 9.1
CVE-2026-34287
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…
Identity Manager Connector
Mitigation only
CRITICAL 9.1
CVE-2026-34286
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…
Identity Manager Connector
Mitigation only
CRITICAL 9.1
CVE-2026-34285
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…
Identity Manager Connector
Mitigation only
CRITICAL 9.1
CVE-2026-34279
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions …
Enterprise Manager Base Platform
Mitigation only
CRITICAL 9.8
CVE-2026-34275
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions …
Advanced Inbound Telephony
after 12.2.15
CRITICAL 9.8
CVE-2026-33519
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…
Portal For Arcgis
Mitigation only
CRITICAL 9.1
CVE-2026-40903
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB…
Goshs
2.0.0+
CRITICAL 9.1
CVE-2026-40887
Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL…
Mitigation only
CRITICAL 9.8
CVE-2026-40884
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username bas…
Goshs
2.0.0+
CRITICAL 9.3
CVE-2026-40872
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs r…
Mitigation only
CRITICAL 9.1
CVE-2026-40372EPSS 11%
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Asp.net Core
10.0.7+
CRITICAL 9.1
CVE-2026-41193
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives…
Patch available
CRITICAL 9.0
CVE-2026-5652
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform …
Crafty Controller
4.10.4+
CRITICAL 9.4
CVE-2026-40576
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions u…
Mitigation only
CRITICAL 9.0
CVE-2026-40569
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connectio…
Patch available
CRITICAL 9.8
CVE-2026-40050
CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne…
Mitigation only