Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6399
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.8
CVE-2026-31883
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders lea…
Freerdp
3.24.0+
CRITICAL 9.8
CVE-2026-31806
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND mes…
Freerdp
3.24.0+
CRITICAL 10.0
CVE-2026-26954
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox…
Sandboxjs
0.8.34+
CRITICAL 9.8
CVE-2026-25823
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stac…
Mitigation only
CRITICAL 9.1
CVE-2026-25818
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak e…
Mitigation only
CRITICAL 9.4
CVE-2026-23941
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin…
Erlang\/inets
9.1.0.5 / 9.3.2.3+
CRITICAL 9.9
CVE-2026-22192
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m…
Wpdiscuz
7.6.47+
CRITICAL 9.8
CVE-2026-1668
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when …
Omada Sg2005p Pd Firmware
1.0.19 / 1.20.17+
CRITICAL 10.0
CVE-2026-3611EPSS 6%
The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n…
Iq4e Firmware
3.30+
CRITICAL 9.8
CVE-2026-32260
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces…
Deno
2.7.2+
CRITICAL 9.8
CVE-2026-32248
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauth…
Parse Server
8.6.38 / 9.6.0+
CRITICAL 9.8
CVE-2026-1525
Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-leng…
Undici
6.24.0 / 7.24.0+
CRITICAL 9.8
CVE-2026-32232
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A…
Zeptoclaw
after 0.7.5
CRITICAL 9.8
CVE-2026-26793
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack…
Ar300m16 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70245
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-28256
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclo…
Tracer Sc\+ Firmware
6.3.2310+
CRITICAL 9.8
CVE-2026-28255
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info…
Tracer Sc Firmware
6.3.2310+
CRITICAL 9.8
CVE-2026-28252
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa…
Tracer Sc Firmware
6.3.2310+
CRITICAL 9.8
CVE-2026-26795
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th…
Ar300m16 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-26792
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe…
Ar300m16 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-26791
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct…
Ar300m16 Firmware
Mitigation only
CRITICAL 9.6
CVE-2026-28792
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al…
Tinacms\/cli
2.1.8+
CRITICAL 9.9
CVE-2026-21708
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
Veeam Backup \& Replication
12.3.2.4465.+
CRITICAL 9.1
CVE-2019-25528
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…
Inout Homestay
No fix yet
CRITICAL 9.1
CVE-2019-25527
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…
Inout Homestay
No fix yet
CRITICAL 9.1
CVE-2019-25526
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…
Inout Homestay
No fix yet
CRITICAL 9.1
CVE-2019-25525
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…
Inout Homestay
No fix yet
CRITICAL 9.1
CVE-2019-25524
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …
Xoogallery
No fix yet
CRITICAL 9.1
CVE-2019-25523
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …
Xoogallery
No fix yet
CRITICAL 9.1
CVE-2019-25522
XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQ…
Xoogallery
No fix yet