Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.8
CVE-2026-4003
The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including …
Mitigation only
CRITICAL 9.8
CVE-2026-3296
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untru…
Mitigation only
CRITICAL 9.8
CVE-2026-27143
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid …
Go
1.25.9 / 1.26.2+
CRITICAL 9.0
CVE-2026-39846
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si…
Siyuan
3.6.4+
CRITICAL 9.1
CVE-2026-34582
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the…
Botan
after 3.11.0
CRITICAL 9.8
CVE-2026-31789
Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impac…
OpenSSL
3.0.20 / 3.3.7+
CRITICAL 10.0
CVE-2026-34078
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options…
Flatpak
after 1.16.3
CRITICAL 9.8
CVE-2026-39397
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers…
Payload Puck
0.6.23+
CRITICAL 9.1
CVE-2026-34045
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…
Podman Desktop
1.26.2+
CRITICAL 9.8
CVE-2026-33439EPSS 10%
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Re…
Openam
16.0.6+
CRITICAL 9.3
CVE-2026-39382
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside th…
Patch available
CRITICAL 9.1
CVE-2025-69515
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS sig…
Mitigation only
CRITICAL 9.1
CVE-2026-39351
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
Frappe
15.104.0 / 16.14.0+
CRITICAL 9.1
CVE-2025-71058
Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configure…
No fix yet
CRITICAL 9.1
CVE-2026-39339
ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (…
Churchcrm
7.1.0+
CRITICAL 10.0
CVE-2026-39337
ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's …
Churchcrm
7.1.0+
CRITICAL 9.8
CVE-2026-39324
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu…
Rack Session
2.1.2+
CRITICAL 9.1
CVE-2026-35573
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo…
Churchcrm
6.5.3+
CRITICAL 9.8
CVE-2026-31272
MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks pro…
Mrcms
Mitigation only
CRITICAL 9.8
CVE-2026-31271
megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The insert() method in UserController.…
Mitigation only
CRITICAL 9.8
CVE-2026-4631EPSS 15%
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitizati…
Mitigation only
CRITICAL 10.0
CVE-2026-39305
PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an att…
Praisonai
after 4.5.112
CRITICAL 9.8
CVE-2026-35614
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…
Frappe
15.104.0 / 16.14.0+
CRITICAL 9.1
CVE-2026-35580
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contr…
Emissary
after 8.38.0
CRITICAL 9.9
CVE-2026-23696EPSS 16%
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allo…
Patch available
CRITICAL 9.8
CVE-2024-36058
The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parame…
Mitigation only
CRITICAL 9.8
CVE-2026-35490
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (…
Changedetection
0.54.8+
CRITICAL 9.8
CVE-2026-33816
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Pgx
5.9.0+
CRITICAL 9.8
CVE-2026-33815
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Pgx
Mitigation only
CRITICAL 9.8
CVE-2025-52908
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…
Exynos W1000 Firmware
Mitigation only