Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.8
CVE-2026-33765
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 …
Web Interface
6.0+
CRITICAL 9.8
CVE-2026-33654
nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module …
Nanobot
0.1.4+
CRITICAL 9.8
CVE-2026-34387
Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an …
Fleet
4.81.1+
CRITICAL 9.1
CVE-2026-34374
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by…
Avideo
after 26.0
CRITICAL 9.8
CVE-2026-4965
A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the…
Letta
Mitigation only
CRITICAL 10.0
CVE-2026-4963
A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the…
Smolagents
Mitigation only
CRITICAL 9.8
CVE-2026-33770
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` con…
Avideo
after 26.0
CRITICAL 9.1
CVE-2026-28369
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28368
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28367
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.8
CVE-2026-30533
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
Online Food Ordering System
Mitigation only
CRITICAL 9.8
CVE-2026-30532
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
Online Food Ordering System
Mitigation only
CRITICAL 9.8
CVE-2026-30530
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer actio…
Online Food Ordering System
Mitigation only
CRITICAL 10.0
CVE-2026-30302
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffec…
Coderider
after 2.3.6
CRITICAL 9.6
CVE-2026-30304
In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f…
Ai Code
after 3.12.4
CRITICAL 9.8
CVE-2026-30303
The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective.…
Axon Code
after 4.123.1
CRITICAL 9.1
CVE-2026-27876
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…
Grafana
11.6.0 / 12.0.0+
CRITICAL 9.3
CVE-2026-1496
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an aut…
Mitigation only
CRITICAL 9.8
CVE-2026-4622
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
Aterm Wg2600hs Firmware
1.3.2 / 1.4.2+
CRITICAL 9.8
CVE-2026-4620
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
Aterm Wx3600hp Firmware
1.4.2 / 1.5.3+
CRITICAL 9.8
CVE-2026-4619
Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
Aterm Wx3600hp Firmware
1.5.3+
CRITICAL 9.8
CVE-2026-25101
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behav…
Bludit
3.17.2+
CRITICAL 9.8
CVE-2026-33280
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionali…
Wcr 1166dhpl Firmware
1.01 / 2.53+
CRITICAL 9.8
CVE-2026-32669
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr…
Wcr 1166dhpl Firmware
1.01 / 2.53+
CRITICAL 9.8
CVE-2026-27650
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be execut…
Wcr 1166dhpl Firmware
1.01 / 2.53+
CRITICAL 9.8
CVE-2026-22738
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious a…
Spring Ai
1.0.5 / 1.1.4+
CRITICAL 9.8
CVE-2026-4908
A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the…
Simple Laundry System
Mitigation only
CRITICAL 9.8
CVE-2026-33890
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitra…
Mytube
1.8.71+
CRITICAL 9.8
CVE-2026-33747
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …
Buildkit
0.28.1+
CRITICAL 9.8
CVE-2026-33729
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to…
Openfga
1.13.1+