Top technology
Linux 13139
Google 12607
Microsoft 12396
Oracle 7285
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2867
Redhat 2620
CRITICAL 9.8
CVE-2026-5849
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a ma…
I12 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-5841
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. E…
I3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-1830EPSS 8%
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffic…
Mitigation only
CRITICAL 9.4
CVE-2026-3199
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with ta…
Mitigation only
CRITICAL 9.8
CVE-2026-5902
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media …
Chrome
147.0.7727.55+
CRITICAL 9.6
CVE-2026-5874
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures …
Chrome
147.0.7727.55+
CRITICAL 9.1
CVE-2026-40035
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug conf…
Unfurl
after 2025.08
CRITICAL 9.8
CVE-2026-39890
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit…
Praisonai
after 4.5.114
CRITICAL 9.8
CVE-2026-39892
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…
Cryptography
46.0.7+
CRITICAL 9.9
CVE-2026-39888
PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", w…
Praisonai
1.5.115+
CRITICAL 9.1
CVE-2026-39429
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cach…
Kcp
0.29.3 / 0.30.3+
CRITICAL 9.9
CVE-2026-35477
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to u…
Inventree
after 1.2.6
CRITICAL 9.8
CVE-2026-2942
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadP…
Mitigation only
CRITICAL 9.8
CVE-2026-33466
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executi…
Logstash
8.19.14 / 9.2.8+
CRITICAL 9.8
CVE-2025-52221
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.
Ac6 Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-31017
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…
Erpnext
Mitigation only
CRITICAL 9.1
CVE-2023-46945
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
Qd
after 20230821
CRITICAL 9.8
CVE-2026-33229
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly p…
Xwiki
17.4.8 / 17.10.1+
CRITICAL 9.8
CVE-2026-31040
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command…
Stata Mcp
1.13.0+
CRITICAL 9.8
CVE-2026-39394
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.4.0+
CRITICAL 9.3
CVE-2025-14816
Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICON…
Mitigation only
CRITICAL 9.3
CVE-2025-14815
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Sui…
Mitigation only
CRITICAL 9.1
CVE-2026-5300
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data …
Coolercontrold
4.0.0+
CRITICAL 9.6
CVE-2026-39640
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from…
Mitigation only
CRITICAL 9.6
CVE-2026-39620
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affec…
Mitigation only
CRITICAL 9.6
CVE-2026-39619
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Bus…
Mitigation only
CRITICAL 9.6
CVE-2026-39617
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestr…
Mitigation only
CRITICAL 9.8
CVE-2026-33088
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
Movable Type
8.0.10 / 8.8.3+
CRITICAL 9.8
CVE-2026-25776
Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.
Movable Type
8.0.10 / 8.8.3+
CRITICAL 9.8
CVE-2026-3535
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownl…
Mitigation only