Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
CRITICAL 9.8
CVE-2026-30993
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnera…
Mitigation only
CRITICAL 9.9
CVE-2026-20186EPSS 6%
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
Identity Services Engine
3.2.0+
CRITICAL 9.8
CVE-2026-20184
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att…
Mitigation only
CRITICAL 9.9
CVE-2026-20180EPSS 6%
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
Identity Services Engine
3.2.0+
CRITICAL 9.9
CVE-2026-20147EPSS 12%
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…
Identity Services Engine Passive Identity Connector
3.1.0+
CRITICAL 9.3
CVE-2025-15610
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed…
Mitigation only
CRITICAL 9.3
CVE-2026-5387
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D…
Mitigation only
CRITICAL 9.8
CVE-2026-30625
Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M…
Patch available
CRITICAL 9.1
CVE-2026-33808
Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options…
Fastify\/express
4.0.5+
CRITICAL 9.1
CVE-2026-33807
@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited…
Fastify\/express
4.0.5+
CRITICAL 9.8
CVE-2026-3461
The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to…
Mitigation only
CRITICAL 9.9
CVE-2026-39842
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engin…
Openremote
1.22.0+
CRITICAL 9.8
CVE-2026-1555
The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v…
Mitigation only
CRITICAL 9.6
CVE-2026-39399
NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi…
Patch available
CRITICAL 9.3
CVE-2026-35589
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's Web…
Nanobot
0.1.5+
CRITICAL 9.1
CVE-2026-35033
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…
Jellyfin
10.11.7+
CRITICAL 9.1
CVE-2026-34457
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authe…
Oauth2 Proxy
7.15.2+
CRITICAL 10.0
CVE-2026-39907
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts un…
Webperfect Image Suite
Mitigation only
CRITICAL 10.0
CVE-2026-39906
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthentic…
Webperfect Image Suite
Mitigation only
CRITICAL 9.3
CVE-2026-27304
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 9.3
CVE-2026-5752
Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain trave…
Mitigation only
CRITICAL 9.3
CVE-2026-34615
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…
Connect
12.11 / 2025.9.15+
CRITICAL 9.8
CVE-2026-33824 KEVEPSS 73%
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
CRITICAL 9.6
CVE-2026-27303
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27246
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27245
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27243
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.0
CVE-2026-26149
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…
Power Apps
3.26032.10.0+
CRITICAL 9.8
CVE-2025-70023
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
Mitigation only
CRITICAL 9.8
CVE-2026-39813EPSS 23%
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…
Fortisandbox
4.4.9 / 5.0.6+