Top technology
Linux 13139
Google 12619
Microsoft 12396
Oracle 7288
Apple 6692
Ibm 6475
Adobe 6390
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2883
Redhat 2620
CRITICAL 9.8
CVE-2025-67114
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG393…
Mitigation only
CRITICAL 9.8
CVE-2025-67113
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo…
Mitigation only
CRITICAL 9.8
CVE-2025-67112
Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware …
Mitigation only
CRITICAL 9.8
CVE-2026-32867
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…
Ecase Ecomplaint
10.1.0.0+
CRITICAL 9.8
CVE-2026-32865
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…
Ecase Ecomplaint
10.1.0.0+
CRITICAL 9.8
CVE-2026-30402
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function
Wgcloud
after 2.3.7
CRITICAL 9.1
CVE-2026-2369
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr…
Libsoup
Patch available
CRITICAL 10.0
CVE-2026-22557EPSS 28%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t…
Mitigation only
CRITICAL 9.1
CVE-2025-71257EPSS 45%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…
Footprints
after 20.24.01.001
CRITICAL 9.8
CVE-2006-10003
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the s…
Xml\
2.48+
CRITICAL 9.1
CVE-2026-27067
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server…
Mitigation only
CRITICAL 9.8
CVE-2026-27065
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build…
Mitigation only
CRITICAL 9.8
CVE-2025-60237
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
Mitigation only
CRITICAL 9.8
CVE-2025-60233
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
Mitigation only
CRITICAL 9.8
CVE-2026-27542
Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P…
Mitigation only
CRITICAL 9.0
CVE-2026-27540
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead…
Mitigation only
CRITICAL 9.3
CVE-2026-27413
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL…
Mitigation only
CRITICAL 10.0
CVE-2026-32737
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…
Romeo
0.2.1+
CRITICAL 9.9
CVE-2026-32731
ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`,
The `extract()` function in `…
Import Export
3.5.3+
CRITICAL 9.1
CVE-2025-15031
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,…
Mlflow
after 3.10.1
CRITICAL 9.8
CVE-2026-31972
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a…
Samtools
1.21.1+
CRITICAL 9.8
CVE-2026-25873
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar…
Patch available
CRITICAL 9.1
CVE-2026-31967
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the…
Htslib
1.21.1 / 1.22.2+
CRITICAL 9.1
CVE-2026-31966
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one…
Htslib
1.21.1 / 1.22.2+
CRITICAL 9.1
CVE-2026-32633
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…
Glances
4.5.2+
CRITICAL 9.1
CVE-2026-32611
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export…
Glances
4.5.2+
CRITICAL 9.1
CVE-2026-30704
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB
Mitigation only
CRITICAL 9.8
CVE-2026-30703
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e…
Mitigation only
CRITICAL 9.8
CVE-2026-30702
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa…
Mitigation only
CRITICAL 9.1
CVE-2026-30701
The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S…
Mitigation only