Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.1
CVE-2025-58349
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…
Exynos 990 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-35171
Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…
Kedro
1.3.0+
CRITICAL 9.8
CVE-2026-35052
D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p…
D Tale
3.22.0+
CRITICAL 9.8
CVE-2026-35047
Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitr…
Bravecms
2.0.6+
CRITICAL 9.6
CVE-2026-35044
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation…
Bentoml
1.4.38+
CRITICAL 9.1
CVE-2026-35039
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not pro…
Fast Jwt
6.1.0+
CRITICAL 9.0
CVE-2026-35035
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.2.0+
CRITICAL 9.1
CVE-2026-35030
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt…
Litellm
1.83.0+
CRITICAL 9.0
CVE-2026-34989
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.0.0+
CRITICAL 9.8
CVE-2026-34977
Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional passw…
Aperisolve
after 3.2.0
CRITICAL 10.0
CVE-2026-34976
Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware…
Dgraph
after 25.3.0
CRITICAL 9.8
CVE-2026-34841
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised version…
Bruno
3.2.1+
CRITICAL 9.1
CVE-2026-34950
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ an…
Fast Jwt
6.2.0+
CRITICAL 10.0
CVE-2026-34444
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc…
Lupa
after 2.6
CRITICAL 10.0
CVE-2026-34208
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), …
Sandboxjs
0.8.36+
CRITICAL 9.8
CVE-2026-5663
A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a…
Dcmtk
after 3.7.0
CRITICAL 9.8
CVE-2026-31151
An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.
Yard Management Solutions
Mitigation only
CRITICAL 9.8
CVE-2026-31059
A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to exec…
520w Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-26263EPSS 9%
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…
Glpi
11.0.6+
CRITICAL 9.8
CVE-2026-31405
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-net: fix OOB access in ULE extension header tables
The ule_mandatory…
Linux Kernel
5.10.253 / 5.15.203+
CRITICAL 9.1
CVE-2019-25704
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the fil…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25702
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25700
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sor…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25698
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25696
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the lan…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25694
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25692
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id…
Kados
No fix yet
CRITICAL 9.1
CVE-2019-25688
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…
Kados
No fix yet
CRITICAL 9.8
CVE-2019-25687
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitr…
Pegasus Cms
Mitigation only
CRITICAL 9.8
CVE-2019-25680
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by …
Advance Gift Shop Pro Script
after 2.0.3