Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 10.0
CVE-2026-28798
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/prox…
Zimaos
1.5.3+
CRITICAL 9.8
CVE-2026-25726
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator …
Cloudreve
4.13.0+
CRITICAL 9.8
CVE-2026-32186
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
Bing
No fix yet
CRITICAL 9.8
CVE-2026-0545
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…
Mlflow
Mitigation only
CRITICAL 9.6
CVE-2026-28373
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when proce…
Stackfield
1.10.2+
CRITICAL 9.0
CVE-2026-35216EPSS 12%
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud…
Budibase
3.33.4+
CRITICAL 9.9
CVE-2026-31818
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d…
Budibase
3.33.4+
CRITICAL 9.8
CVE-2026-31402
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
The NFSv4.0 replay cache u…
Linux Kernel
5.10.253 / 6.1.167+
CRITICAL 9.1
CVE-2026-23455
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
In DecodeQ9…
Linux Kernel
5.10.253 / 5.15.203+
CRITICAL 9.8
CVE-2026-23450
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
Syzkaller repo…
Linux Kernel
5.15.203 / 6.1.167+
CRITICAL 9.8
CVE-2026-5463
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline charact…
Pymetasploit3
after 1.0.6
CRITICAL 9.8
CVE-2026-33107
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Azure Databricks
Mitigation only
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.8
CVE-2026-35053
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio…
Oneuptime
10.0.42+
CRITICAL 9.3
CVE-2026-34932
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…
Hoppscotch
2026.3.0+
CRITICAL 9.6
CVE-2026-34931
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…
Hoppscotch
2026.3.0+
CRITICAL 9.9
CVE-2026-34838
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability i…
Group Office
6.8.156 / 25.0.90+
CRITICAL 9.8
CVE-2024-14034
Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauth…
Mitigation only
CRITICAL 9.1
CVE-2026-34758
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu…
Oneuptime
10.0.40+
CRITICAL 9.1
CVE-2026-34745
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/up…
Fireshare
1.5.3+
CRITICAL 9.8
CVE-2026-5368
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the com…
Car Rental Project
Mitigation only
CRITICAL 9.8
CVE-2026-34877
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session st…
Mbed Tls
3.6.6+
CRITICAL 9.4
CVE-2026-33950
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…
Signal K Server
2.24.0+
CRITICAL 9.9
CVE-2026-25212
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admi…
Monitoring And Management
3.7.0+
CRITICAL 9.8
CVE-2026-33746
Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did …
Convoy
4.5.1+
CRITICAL 9.8
CVE-2026-35002
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arb…
Agno
2.3.24+
CRITICAL 10.0
CVE-2026-32871
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clien…
Fastmcp
3.2.0+
CRITICAL 9.8
CVE-2026-5334
A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=e…
Online Enrollment System
Mitigation only
CRITICAL 9.8
CVE-2026-5333
A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/to…
Content Management System
Mitigation only