Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.3
CVE-2025-41008
SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client'…
Mitigation only
CRITICAL 9.8
CVE-2026-31851
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication int…
Nebula300plus Firmware
after 12.01.01.37
CRITICAL 9.8
CVE-2026-31848
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential…
Nebula300plus Firmware
after 12.01.01.37
CRITICAL 9.3
CVE-2025-41007
SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in th…
Mitigation only
CRITICAL 9.8
CVE-2026-4585
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy…
Mitigation only
CRITICAL 9.8
CVE-2026-32968
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in …
Mitigation only
CRITICAL 9.8
CVE-2026-4581
A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the compone…
Simple Laundry System
Mitigation only
CRITICAL 9.8
CVE-2026-4580
A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php o…
Simple Laundry System
Mitigation only
CRITICAL 9.8
CVE-2026-4579
A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the compon…
Simple Laundry System
Mitigation only
CRITICAL 10.0
CVE-2026-3587
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of …
Mitigation only
CRITICAL 9.1
CVE-2026-4601
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in t…
Jsrsasign
11.1.1+
CRITICAL 9.1
CVE-2026-4600
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid…
Jsrsasign
11.1.1+
CRITICAL 9.1
CVE-2026-4599
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigInteg…
Jsrsasign
11.1.1+
CRITICAL 9.8
CVE-2026-4567
A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulat…
A15 Firmware
Mitigation only
CRITICAL 10.0
CVE-2026-4606
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full cont…
Mitigation only
CRITICAL 9.8
CVE-2019-25614
Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sen…
Freefloat Ftp Server
Mitigation only
CRITICAL 9.1
CVE-2026-32064
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…
Openclaw
2026.2.21+
CRITICAL 9.8
CVE-2026-32056
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac…
Openclaw
2026.2.22+
CRITICAL 9.8
CVE-2026-32052
OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde…
Openclaw
2026.2.24+
CRITICAL 9.9
CVE-2026-32048
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …
Openclaw
2026.3.1+
CRITICAL 9.8
CVE-2026-32046
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo…
Openclaw
2026.2.21+
CRITICAL 9.1
CVE-2026-32045
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and…
Openclaw
2026.2.21+
CRITICAL 9.1
CVE-2026-24060
Service information is not encrypted when transmitted as BACnet packets
over the wire, and can be sniffed, intercepted, and modified by an
attacker…
Mitigation only
CRITICAL 9.8
CVE-2026-33228
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed …
Flatted
3.4.2+
CRITICAL 9.1
CVE-2026-33210
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnera…
Json
2.15.2.1 / 2.17.1.2+
CRITICAL 9.1
CVE-2026-33186
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of …
Grpc
1.79.3+
CRITICAL 9.8
CVE-2026-29796
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Eparking.fi
Mitigation only
CRITICAL 9.8
CVE-2026-25192
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Charge Portal
Mitigation only
CRITICAL 9.6
CVE-2026-21732
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU…
Ddk
after 25.1
CRITICAL 9.8
CVE-2026-3584EPSS 7%
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio…
Mitigation only