Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6405
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.6
CVE-2026-3916
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a craf…
Chrome
146.0.7680.71+
CRITICAL 9.8
CVE-2026-32136
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic…
Adguardhome
0.107.73+
CRITICAL 9.1
CVE-2026-32133
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability …
2fauth
6.1.0+
CRITICAL 9.9
CVE-2026-27591
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al…
Winter
1.0.477 / 1.1.12+
CRITICAL 9.0
CVE-2026-32118
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scriptin…
Openemr
8.0.0.1+
CRITICAL 9.8
CVE-2025-70041
An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.
Mitigation only
CRITICAL 9.8
CVE-2025-70024
An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.
Mitigation only
CRITICAL 9.9
CVE-2025-66956
Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachme…
Mitigation only
CRITICAL 9.8
CVE-2026-31976
xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull …
Xygeni Action
after 6.4.0
CRITICAL 10.0
CVE-2026-31957
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a conf…
Himmelblau
3.1.0+
CRITICAL 9.8
CVE-2026-31900
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject:…
Black
26.3.0+
CRITICAL 9.8
CVE-2026-31896
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. T…
Wegia
3.6.6+
CRITICAL 9.8
CVE-2026-27703
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…
Riot
after 2026.01
CRITICAL 9.1
CVE-2026-27478
Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Uni…
Unitycatalog
after 0.4.0
CRITICAL 9.8
CVE-2026-31881
Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re…
Runtipi
4.8.0+
CRITICAL 9.8
CVE-2026-31877
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…
Frappe
14.99.0 / 15.84.0+
CRITICAL 9.8
CVE-2026-31874
Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly…
Taskosaur
Patch available
CRITICAL 9.8
CVE-2019-25487EPSS 8%
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands b…
Mitigation only
CRITICAL 9.8
CVE-2019-25471
FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the…
File Thingie
after 2.5.7
CRITICAL 9.8
CVE-2019-25468
NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by …
Mitigation only
CRITICAL 9.8
CVE-2018-25159
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated att…
Mitigation only
CRITICAL 9.8
CVE-2026-31975
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection v…
Cloud Cli
1.25.0+
CRITICAL 9.8
CVE-2026-31871
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL inje…
Parse Server
8.6.31 / 9.6.0+
CRITICAL 9.8
CVE-2026-31856
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the P…
Parse Server
8.6.29 / 9.6.0+
CRITICAL 9.8
CVE-2026-31852
Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…
Jellyfin
Patch available
CRITICAL 9.8
CVE-2026-31840
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacke…
Parse Server
8.6.28 / 9.6.0+
CRITICAL 9.8
CVE-2026-1524
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…
Neo4j
5.26.22 / 2026.02+
CRITICAL 9.8
CVE-2025-70082
An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component
Eds3016ps1ns Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-67041
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti…
Eds3016ps1ns Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-67039
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to th…
Eds3016ps1ns Firmware
Mitigation only