Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.8
CVE-2026-33728
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a cus…
Dd Trace Java
1.60.3+
CRITICAL 9.9
CVE-2026-33718
OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method a…
Openhands
1.5.0+
CRITICAL 9.8
CVE-2026-33701
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t…
Opentelemetry Instrumentation For Java
2.26.1+
CRITICAL 9.6
CVE-2026-33945
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container…
Incus
6.23.0+
CRITICAL 9.8
CVE-2026-34352
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, b…
Tigervnc
1.16.2+
CRITICAL 9.9
CVE-2026-33897
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writ…
Incus
6.23.0+
CRITICAL 9.8
CVE-2026-33640
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identit…
Outline
1.6.0+
CRITICAL 9.1
CVE-2026-30458
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
Fuel Cms
No fix yet
CRITICAL 9.8
CVE-2026-30457
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Dwoo
Mitigation only
CRITICAL 9.8
CVE-2026-26213EPSS 6%
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive p…
Thingino Firmware
after 2026-03-15
CRITICAL 10.0
CVE-2026-33494
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versi…
Oathkeeper
26.2.0+
CRITICAL 9.1
CVE-2026-27816
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable…
Everest
2026.02.0+
CRITICAL 9.1
CVE-2026-27815
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment…
Everest
2026.02.0+
CRITICAL 9.9
CVE-2026-33396
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can …
Oneuptime
10.0.35+
CRITICAL 9.8
CVE-2025-55261
HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…
Aftermarket Cloud
Mitigation only
CRITICAL 9.8
CVE-2025-55270
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…
Aftermarket Cloud
Mitigation only
CRITICAL 9.8
CVE-2025-55269
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force…
Aftermarket Cloud
Mitigation only
CRITICAL 9.8
CVE-2025-55267
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…
Aftermarket Cloud
Mitigation only
CRITICAL 9.8
CVE-2018-25204
Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through …
Library Cms
Mitigation only
CRITICAL 9.8
CVE-2018-25201
School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authenticat…
School Management System Cms
Mitigation only
CRITICAL 9.8
CVE-2018-25195
Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authen…
Hotel Cms
Mitigation only
CRITICAL 9.8
CVE-2018-25185
Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting …
Restaurant Cms
Mitigation only
CRITICAL 9.8
CVE-2018-25183
Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code …
Shipping System Cms
Mitigation only
CRITICAL 9.8
CVE-2026-4809
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a cli…
Mitigation only
CRITICAL 9.8
CVE-2026-4850
A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checkregisitem.php of th…
Simple Laundry System
Mitigation only
CRITICAL 9.8
CVE-2014-125112
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution.
Plack::Middleware::Session::Cookie versions through …
Plack\
0.23+
CRITICAL 9.8
CVE-2026-33942
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAut…
Saloon
4.0.0+
CRITICAL 9.1
CVE-2026-33183
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file path…
Saloon
4.0.0+
CRITICAL 9.8
CVE-2026-30975
Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled au…
Sonarr
4.0.16.2942+
CRITICAL 9.8
CVE-2025-14917
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu…
Websphere Application Server
26.0.0.4+