Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.9
CVE-2026-25345
Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality…
Mitigation only
CRITICAL 9.3
CVE-2026-25340
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind…
Mitigation only
CRITICAL 9.8
CVE-2026-25035
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery…
Mitigation only
CRITICAL 9.8
CVE-2026-25032
Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.3…
Mitigation only
CRITICAL 9.8
CVE-2026-25031
Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from …
Mitigation only
CRITICAL 9.8
CVE-2026-25030
Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through…
Mitigation only
CRITICAL 9.8
CVE-2026-25029
Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.
Mitigation only
CRITICAL 9.3
CVE-2026-24993
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Re…
Mitigation only
CRITICAL 9.8
CVE-2026-24989
Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliat…
Mitigation only
CRITICAL 9.8
CVE-2026-24971
Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n…
Mitigation only
CRITICAL 9.8
CVE-2026-24968
Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a thro…
Mitigation only
CRITICAL 9.8
CVE-2026-24378
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affec…
Mitigation only
CRITICAL 9.8
CVE-2026-22507
Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through …
Mitigation only
CRITICAL 9.8
CVE-2026-22500
Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 …
Mitigation only
CRITICAL 9.3
CVE-2026-22484
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL …
Mitigation only
CRITICAL 9.8
CVE-2026-26833
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c…
Thumbler
after 1.1.2
CRITICAL 9.8
CVE-2026-26832
node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in sr…
Tesseract Ocr
after 2.2.1
CRITICAL 9.8
CVE-2026-26831
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious…
Textract
after 2.5.0
CRITICAL 9.8
CVE-2026-26830
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon…
Pdf Image
after 2.0.0
CRITICAL 9.8
CVE-2025-59707
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerabilit…
N2w
4.3.2+
CRITICAL 9.8
CVE-2025-59706
In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
N2w
4.3.2+
CRITICAL 9.0
CVE-2025-32991
In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
Backup\& Recovery
4.3.2+
CRITICAL 9.8
CVE-2026-4784
A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the componen…
Simple Laundry System
Mitigation only
CRITICAL 9.8
CVE-2026-28858
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause un…
Ipados
26.4+
CRITICAL 9.3
CVE-2026-28827
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS So…
macOS
14.8.5 / 15.7.5+
CRITICAL 9.3
CVE-2026-20688
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.…
Ipados
14.8.5 / 15.7.5+
CRITICAL 9.8
CVE-2026-24159
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might le…
Nemo
2.6.2+
CRITICAL 9.8
CVE-2026-24157
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of thi…
Nemo
2.6.2+
CRITICAL 9.0
CVE-2025-33244
NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability aff…
Mitigation only
CRITICAL 9.8
CVE-2026-33511
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator i…
Pyload Ng
0.5.0b3.dev97+