Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6399
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.1
CVE-2025-15031
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,…
Mlflow
after 3.10.1
CRITICAL 9.8
CVE-2026-31972
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a…
Samtools
1.21.1+
CRITICAL 9.8
CVE-2026-25873
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar…
Patch available
CRITICAL 9.1
CVE-2026-31967
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the…
Htslib
1.21.1 / 1.22.2+
CRITICAL 9.1
CVE-2026-31966
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one…
Htslib
1.21.1 / 1.22.2+
CRITICAL 9.1
CVE-2026-32633
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…
Glances
4.5.2+
CRITICAL 9.1
CVE-2026-32611
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export…
Glances
4.5.2+
CRITICAL 9.1
CVE-2026-30704
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB
Mitigation only
CRITICAL 9.8
CVE-2026-30703
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e…
Mitigation only
CRITICAL 9.8
CVE-2026-30702
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa…
Mitigation only
CRITICAL 9.1
CVE-2026-30701
The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S…
Mitigation only
CRITICAL 9.8
CVE-2026-29859
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.
Aapanel
Mitigation only
CRITICAL 9.8
CVE-2025-67830
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
Mura Cms
10.1.4+
CRITICAL 9.8
CVE-2025-67829
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
Mura Cms
10.1.4+
CRITICAL 9.8
CVE-2026-25449
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through…
Mitigation only
CRITICAL 9.0
CVE-2026-33265
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
Librechat
No fix yet
CRITICAL 9.6
CVE-2026-30884
mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P…
Patch available
CRITICAL 9.1
CVE-2026-28500
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security con…
Onnx
after 1.20.1
CRITICAL 9.1
CVE-2026-22171
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol…
Openclaw
2026.2.19+
CRITICAL 9.8
CVE-2026-27459
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set…
Pyopenssl
26.0.0+
CRITICAL 9.1
CVE-2026-3856
IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for …
Db2 Recovery Expert
Patch available
CRITICAL 9.8
CVE-2026-21994
Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop).…
Okit
Mitigation only
CRITICAL 9.8
CVE-2026-3207
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Bpm Enterprise
4.3.5+
CRITICAL 9.8
CVE-2026-4319
A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file …
Simple Food Order System
Mitigation only
CRITICAL 9.1
CVE-2026-32298
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute O…
Es3 Kvm Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-25769EPSS 9%
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execut…
Wazuh
4.14.3+
CRITICAL 9.1
CVE-2026-25534
### Impact
Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed th…
Patch available
CRITICAL 9.0
CVE-2026-3564
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob…
Mitigation only
CRITICAL 9.8
CVE-2026-4312
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces…
Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software
Mitigation only
CRITICAL 9.1
CVE-2026-4177
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML e…
Yaml\
1.37+