Top technology
Linux 13139
Google 12607
Microsoft 12396
Oracle 7285
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2867
Redhat 2620
CRITICAL 9.3
CVE-2026-27304
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 9.3
CVE-2026-5752
Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain trave…
Mitigation only
CRITICAL 9.3
CVE-2026-34615
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…
Connect
12.11 / 2025.9.15+
CRITICAL 9.8
CVE-2026-33824 KEVEPSS 73%
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
CRITICAL 9.6
CVE-2026-27303
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27246
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27245
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.3
CVE-2026-27243
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…
Connect
12.11 / 2025.9.15+
CRITICAL 9.0
CVE-2026-26149
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…
Power Apps
3.26032.10.0+
CRITICAL 9.8
CVE-2025-70023
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
Mitigation only
CRITICAL 9.8
CVE-2026-39813EPSS 23%
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…
Fortisandbox
4.4.9 / 5.0.6+
CRITICAL 9.8
CVE-2026-39808 KEVEPSS 93%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…
Fortisandbox
after 4.4.9
CRITICAL 9.9
CVE-2026-38526
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute ar…
Mitigation only
CRITICAL 9.8
CVE-2025-65135
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.p…
Mitigation only
CRITICAL 9.8
CVE-2025-65133
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attac…
Mitigation only
CRITICAL 9.8
CVE-2025-63939
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the si…
Mitigation only
CRITICAL 9.8
CVE-2025-61260EPSS 7%
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) conf…
Mitigation only
CRITICAL 9.8
CVE-2026-31049
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration …
Mitigation only
CRITICAL 9.1
CVE-2025-8095
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuita…
Mitigation only
CRITICAL 9.0
CVE-2026-2449
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Acc…
Mitigation only
CRITICAL 9.1
CVE-2026-2332
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques out…
Jetty
9.4.60 / 10.0.28+
CRITICAL 9.1
CVE-2026-31908
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…
Apisix
3.16.0+
CRITICAL 9.8
CVE-2026-40315
PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta…
Praisonai
4.5.133+
CRITICAL 9.1
CVE-2026-40313
PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cre…
Praisonai
4.5.140+
CRITICAL 9.1
CVE-2026-40289
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser…
Praisonaiagents
1.5.140 / 4.5.139+
CRITICAL 9.8
CVE-2026-40288
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to …
Praisonaiagents
1.5.140 / 4.5.139+
CRITICAL 9.8
CVE-2026-6264
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The att…
Mitigation only
CRITICAL 9.1
CVE-2026-4365
The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` f…
Mitigation only
CRITICAL 9.9
CVE-2026-27681
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute cra…
Mitigation only
CRITICAL 9.8
CVE-2026-22564
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized chang…
Mitigation only