Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6399
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.8
CVE-2026-4182
A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the com…
Dir 816 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-4181
A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the c…
Dir 816 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-4180
A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goa…
Dir 816 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-4170
A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage…
Mitigation only
CRITICAL 9.8
CVE-2026-4164
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of t…
Mitigation only
CRITICAL 9.8
CVE-2026-4163
A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the…
Mitigation only
CRITICAL 9.0
CVE-2026-32635
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n…
Angular Cli
19.2.0 / 21.2.4+
CRITICAL 9.6
CVE-2026-32626
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An…
Anythingllm
after 1.11.1
CRITICAL 9.8
CVE-2026-32640
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul…
Simpleeval
1.0.5+
CRITICAL 9.9
CVE-2026-32621
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vul…
Mitigation only
CRITICAL 9.8
CVE-2026-20998
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
Smart Switch
3.7.69.15+
CRITICAL 9.8
CVE-2026-20997
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat…
Smart Switch
3.7.69.15+
CRITICAL 9.8
CVE-2025-69246
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without tr…
Raytha
1.4.6+
CRITICAL 9.8
CVE-2025-52648
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp…
Aion
2.1.2+
CRITICAL 9.8
CVE-2025-15060
claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…
Mitigation only
CRITICAL 9.8
CVE-2017-20224
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…
Sdt Cs3b1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-20223
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…
Sdt Cs3b1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-20030
ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting pa…
Mitigation only
CRITICAL 9.8
CVE-2016-20026
ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage…
Mitigation only
CRITICAL 9.8
CVE-2016-20024
ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying exec…
Mitigation only
CRITICAL 9.8
CVE-2015-20121
Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by …
Realtyscript
Mitigation only
CRITICAL 9.8
CVE-2015-20120
Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra…
Realtyscript
Mitigation only
CRITICAL 9.8
CVE-2026-3891EPSS 25%
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation…
Mitigation only
CRITICAL 9.8
CVE-2026-32746EPSS 24%
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does …
Inetutils
after 2.7
CRITICAL 9.1
CVE-2026-32367
Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th…
Mitigation only
CRITICAL 9.9
CVE-2026-32306
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregat…
Oneuptime
10.0.23+
CRITICAL 9.8
CVE-2026-32304
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…
Locutus
3.0.14+
CRITICAL 9.3
CVE-2026-32301
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when…
Centrifugo
6.7.0+
CRITICAL 9.1
CVE-2026-31897
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar …
Freerdp
3.24.0+
CRITICAL 9.4
CVE-2026-31885
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders d…
Freerdp
3.24.0+