Top technology
Linux 13139
Google 12607
Microsoft 12396
Oracle 7285
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2867
Redhat 2620
CRITICAL 9.6
CVE-2026-40088
PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled i…
Praisonai
4.5.121+
CRITICAL 9.1
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…
Tomcat
1.3.7 / 2.0.14+
CRITICAL 9.8
CVE-2025-13926
An attacker could use data obtained by sniffing the network traffic to
forge packets in order to make arbitrary requests to Contemporary
Controls B…
Mitigation only
CRITICAL 9.1
CVE-2026-39912
V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the …
Patch available
CRITICAL 9.9
CVE-2026-34987
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler back…
Wasmtime
36.0.7 / 42.0.2+
CRITICAL 9.8
CVE-2026-31170
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame…
A3300r Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-28205
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…
Openplc V3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-5971
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action…
Metagpt
after 0.8.1
CRITICAL 9.8
CVE-2026-5970
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB…
Metagpt
after 0.8.1
CRITICAL 9.8
CVE-2026-39987 KEVEPSS 97%
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…
Marimo
0.23.0+
CRITICAL 9.8
CVE-2026-5962
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The ma…
Ch22 Firmware
Mitigation only
CRITICAL 9.6
CVE-2026-39962
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in Apa…
Misp
2.5.36+
CRITICAL 9.1
CVE-2026-39958
oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic…
Patch available
CRITICAL 9.1
CVE-2026-30479
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted execut…
Mitigation only
CRITICAL 9.1
CVE-2025-15480
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a use…
Ubuntu Desktop Provision
Patch available
CRITICAL 9.1
CVE-2026-5445
An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used f…
Orthanc
1.12.11+
CRITICAL 9.8
CVE-2026-5443
A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication f…
Orthanc
1.12.11+
CRITICAL 9.8
CVE-2026-5442
A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (U…
Orthanc
1.12.11+
CRITICAL 9.9
CVE-2025-62718
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization …
Axios
0.31.0 / 1.15.0+
CRITICAL 9.1
CVE-2025-50228
Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
Jizhicms
Mitigation only
CRITICAL 9.1
CVE-2025-57735
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte…
Airflow
3.2.0+
CRITICAL 9.1
CVE-2026-34184
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and ev…
Control System
9.8.5+
CRITICAL 9.1
CVE-2026-34179
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PU…
Lxd
after 6.7
CRITICAL 9.1
CVE-2026-34178
In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates …
Lxd
after 6.7
CRITICAL 9.1
CVE-2026-34177
Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omit…
Lxd
after 6.7
CRITICAL 9.8
CVE-2026-5854EPSS 18%
A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cst…
Mitigation only
CRITICAL 9.8
CVE-2026-5853EPSS 14%
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of …
Mitigation only
CRITICAL 9.8
CVE-2026-5852EPSS 14%
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the …
Mitigation only
CRITICAL 9.8
CVE-2026-5851EPSS 14%
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi o…
Mitigation only
CRITICAL 9.8
CVE-2026-5850EPSS 16%
A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of …
Mitigation only