Top technology
Linux 13139
Google 12676
Microsoft 12396
Oracle 7344
Apple 6695
Ibm 6475
Adobe 6405
Cisco 5759
Debian 3920
Mozilla 2912
Apache 2909
Redhat 2620
CRITICAL 9.9
CVE-2026-30956
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol…
Oneuptime
10.0.21+
CRITICAL 9.8
CVE-2026-30930
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string co…
Glances
4.5.1+
CRITICAL 9.3
CVE-2026-26105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20076+
CRITICAL 9.8
CVE-2026-23240
In the Linux kernel, the following vulnerability has been resolved:
tls: Fix race condition in tls_sw_cancel_work_tx()
This issue was discovered du…
Linux Kernel
6.12.75 / 6.18.16+
CRITICAL 9.1
CVE-2025-69615
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. …
Account Management Portal
after 2025-10-24
CRITICAL 9.4
CVE-2025-69614
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. A…
Account Management Portal
2025-10-27+
CRITICAL 9.8
CVE-2025-56422
A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.
Limesurvey
after 6.14.3
CRITICAL 9.8
CVE-2025-41709
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.
Mitigation only
CRITICAL 9.6
CVE-2025-40943
Affected devices do not properly sanitize contents of trace files.
This could allow an attacker to inject code through social engineering an autho…
Mitigation only
CRITICAL 9.9
CVE-2026-30921
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project user…
Oneuptime
10.0.20+
CRITICAL 9.9
CVE-2026-30887
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/Java…
Oneuptime
10.0.18+
CRITICAL 9.8
CVE-2026-30869
SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read …
Siyuan
3.5.10+
CRITICAL 9.0
CVE-2026-30862
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table …
Appsmith
1.96+
CRITICAL 9.1
CVE-2026-27685
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, …
Mitigation only
CRITICAL 9.8
CVE-2026-0953
The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.…
Mitigation only
CRITICAL 9.1
CVE-2025-11158
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT …
Vantara Pentaho Data Integration And Analytics
10.2.0.6+
CRITICAL 9.1
CVE-2026-31816EPSS 15%
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() m…
Budibase
after 3.31.4
CRITICAL 9.8
CVE-2026-25960
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in…
Vllm
0.17.0+
CRITICAL 9.0
CVE-2026-25737
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili…
Budibase
after 3.24.0
CRITICAL 9.8
CVE-2025-70039
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Twake
Mitigation only
CRITICAL 9.8
CVE-2025-70046
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.
Oa Font Service
No fix yet
CRITICAL 9.8
CVE-2025-70042
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.
Thermakube
Mitigation only
CRITICAL 9.8
CVE-2026-3818
A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This mani…
Easy7 Cms
Mitigation only
CRITICAL 9.8
CVE-2026-3813
A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calcula…
Jflow
Mitigation only
CRITICAL 9.8
CVE-2025-40639
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases thr…
Eventobot
Mitigation only
CRITICAL 9.8
CVE-2026-24713
Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users a…
Iotdb
1.3.7 / 2.0.7+
CRITICAL 9.8
CVE-2026-24015
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrad…
Iotdb
1.3.7 / 2.0.7+
CRITICAL 9.1
CVE-2025-41765
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d…
Universal Bacnet Router Firmware
6.0.1.0+
CRITICAL 9.1
CVE-2025-41764
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u…
Universal Bacnet Router Firmware
6.0.1.0+
CRITICAL 9.8
CVE-2026-3823
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to co…
Atop Ehg2408 Firmware
3.36+