Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-75843
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated …
No fix yet
CRITICAL 9.1
CVE-2026-75837
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi…
No fix yet
CRITICAL 9.8
CVE-2026-75627
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication fil…
Patch available
CRITICAL 9.3
CVE-2026-75626
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …
No fix yet
CRITICAL 9.8
CVE-2026-34884
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking M…
No fix yet
CRITICAL 9.8
CVE-2026-15748
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…
No fix yet
CRITICAL 9.1
CVE-2026-75094
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid…
No fix yet
CRITICAL 9.8
CVE-2026-67919
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli…
No fix yet
CRITICAL 9.8
CVE-2026-42164
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…
No fix yet
CRITICAL 9.1
CVE-2026-42162
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact…
No fix yet
CRITICAL 9.8
CVE-2026-38165
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t…
Patch available
CRITICAL 9.8
CVE-2026-67960
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C…
No fix yet
CRITICAL 9.6
CVE-2026-71424
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…
Patch available
CRITICAL 9.8
CVE-2026-67868
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This…
No fix yet
CRITICAL 9.8
CVE-2026-67854
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
No fix yet
CRITICAL 9.3
CVE-2026-64849 KEVEPSS 8%
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated…
Mlflow
3.15.0+
CRITICAL 9.1
CVE-2026-51977
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the…
No fix yet
CRITICAL 9.8
CVE-2026-42163
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…
No fix yet
CRITICAL 9.8
CVE-2026-75110
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, d…
No fix yet
CRITICAL 9.1
CVE-2026-75106
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attack…
Patch available
CRITICAL 9.8
CVE-2026-67967
Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-448…
No fix yet
CRITICAL 9.8
CVE-2026-67966
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces…
No fix yet
CRITICAL 9.8
CVE-2026-67965
An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function
No fix yet
CRITICAL 9.8
CVE-2026-67926
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
No fix yet
CRITICAL 9.8
CVE-2026-67917
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma…
No fix yet
CRITICAL 9.1
CVE-2026-66795
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR…
No fix yet
CRITICAL 9.9
CVE-2026-65974
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permissio…
Patch available
CRITICAL 9.8
CVE-2026-47698
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Funct…
Patch available
CRITICAL 9.9
CVE-2026-47686
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedE…
Patch available
CRITICAL 9.8
CVE-2026-39255
Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_…
No fix yet