Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.1
CVE-2026-34359
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtil…
Hl7 Fhir Core
6.9.4+
CRITICAL 9.8
CVE-2026-24164
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh…
Bionemo Framework
2026-01-21+
CRITICAL 9.4
CVE-2026-24148
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization …
Jetson Linux
35.6.4 / 36.5+
CRITICAL 9.8
CVE-2026-34243
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action…
Wenxian
after 0.3.1
CRITICAL 9.1
CVE-2026-34235
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists …
Pjsip
2.17+
CRITICAL 9.1
CVE-2026-34221
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototyp…
Mikroorm
6.6.10 / 7.0.6+
CRITICAL 9.8
CVE-2026-34220
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a…
Mikroorm
6.6.10 / 7.0.6+
CRITICAL 9.8
CVE-2026-30281
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, …
Neo.maru
Mitigation only
CRITICAL 9.8
CVE-2026-30276
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file imp…
Document Translator
Mitigation only
CRITICAL 9.1
CVE-2026-34532
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, …
Parse Server
8.6.67 / 9.7.0+
CRITICAL 10.0
CVE-2026-34162
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp…
Fastgpt
4.14.9.5+
CRITICAL 9.9
CVE-2026-33579
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…
Openclaw
2026.3.28+
CRITICAL 9.8
CVE-2026-30314
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…
Auto Approval Module
after 0.1.1
CRITICAL 9.8
CVE-2026-30312
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…
Mitigation only
CRITICAL 9.8
CVE-2026-30311
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…
Auto Approval Module
after 0.1.1
CRITICAL 9.9
CVE-2026-34156EPSS 35%
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's …
Nocobase
2.0.28+
CRITICAL 9.8
CVE-2026-30310
In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for…
Mitigation only
CRITICAL 9.8
CVE-2026-32917
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute …
Openclaw
2026.3.13+
CRITICAL 9.8
CVE-2026-32916
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug…
Openclaw
2026.3.11+
CRITICAL 9.1
CVE-2025-15618
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key.
Business::OnlinePayment::StoredTransaction ge…
Business\
Patch available
CRITICAL 9.3
CVE-2026-4317
SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated at…
Mitigation only
CRITICAL 9.1
CVE-2025-10559
A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele…
3dexperience
Mitigation only
CRITICAL 9.8
CVE-2026-5183EPSS 7%
A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Exec…
Tew 713re Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-34060
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub…
Ruby Lsp
0.10.2 / 0.26.9+
CRITICAL 9.8
CVE-2026-34041
act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: …
Act
0.2.86+
CRITICAL 9.8
CVE-2026-32714
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL In…
Scitokens Library
1.9.6+
CRITICAL 9.8
CVE-2026-5176
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi…
A3300r Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-3300EPSS 41%
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12…
Mitigation only
CRITICAL 9.8
CVE-2026-30880
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue …
Basercms
5.2.3+
CRITICAL 9.8
CVE-2026-27697
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been pa…
Basercms
5.2.3+