Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6399
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.8
CVE-2026-32191
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…
Bing Images
Mitigation only
CRITICAL 9.8
CVE-2026-32169
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
Azure Cloud Shell
Mitigation only
CRITICAL 9.6
CVE-2026-30924
qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins whi…
Qui
1.15.0+
CRITICAL 10.0
CVE-2026-30836
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag…
Step Ca
0.30.0+
CRITICAL 9.8
CVE-2026-27953
ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing …
Ormar
0.23.1+
CRITICAL 10.0
CVE-2026-26138
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
Mitigation only
CRITICAL 9.9
CVE-2026-26137
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
365 Copilot Chat
No fix yet
CRITICAL 9.8
CVE-2026-23658
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
No fix yet
CRITICAL 9.1
CVE-2026-32238
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command …
Openemr
8.0.0.2+
CRITICAL 9.8
CVE-2026-3548
Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when imprope…
Wolfssl
5.9.0+
CRITICAL 9.8
CVE-2026-30694
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
Dedecms
after 5.7.118
CRITICAL 9.8
CVE-2025-67114
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG393…
Mitigation only
CRITICAL 9.8
CVE-2025-67113
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo…
Mitigation only
CRITICAL 9.8
CVE-2025-67112
Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware …
Mitigation only
CRITICAL 9.8
CVE-2026-32867
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…
Ecase Ecomplaint
10.1.0.0+
CRITICAL 9.8
CVE-2026-32865
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…
Ecase Ecomplaint
10.1.0.0+
CRITICAL 9.8
CVE-2026-30402
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function
Wgcloud
after 2.3.7
CRITICAL 9.1
CVE-2026-2369
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr…
Libsoup
Patch available
CRITICAL 10.0
CVE-2026-22557EPSS 28%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t…
Mitigation only
CRITICAL 9.1
CVE-2025-71257EPSS 45%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…
Footprints
after 20.24.01.001
CRITICAL 9.8
CVE-2006-10003
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the s…
Xml\
2.48+
CRITICAL 9.1
CVE-2026-27067
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server…
Mitigation only
CRITICAL 9.8
CVE-2026-27065
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build…
Mitigation only
CRITICAL 9.8
CVE-2025-60237
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
Mitigation only
CRITICAL 9.8
CVE-2025-60233
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
Mitigation only
CRITICAL 9.8
CVE-2026-27542
Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P…
Mitigation only
CRITICAL 9.0
CVE-2026-27540
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead…
Mitigation only
CRITICAL 9.3
CVE-2026-27413
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL…
Mitigation only
CRITICAL 10.0
CVE-2026-32737
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…
Romeo
0.2.1+
CRITICAL 9.9
CVE-2026-32731
ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`,
The `extract()` function in `…
Import Export
3.5.3+