Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.1
CVE-2026-30832
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the s…
Soft Serve
0.11.4+
CRITICAL 9.3
CVE-2026-29191
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered …
Zitadel
4.12.0+
CRITICAL 9.8
CVE-2026-29186
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…
Backstage Plugin Techdocs Node
1.14.3+
CRITICAL 9.3
CVE-2026-29067
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese…
Zitadel
4.7.1+
CRITICAL 9.8
CVE-2026-30824EPSS 36%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid…
Flowise
3.0.13+
CRITICAL 9.8
CVE-2026-30821EPSS 15%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId…
Flowise
3.0.13+
CRITICAL 9.8
CVE-2026-25072
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogi…
Zikestor Sks8310 8x Firmware
after 1.04.b07
CRITICAL 9.8
CVE-2026-25070
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp…
Zikestor Sks8310 8x Firmware
after 1.04.b07
CRITICAL 9.8
CVE-2026-29063
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immuta…
Immutable
3.8.3 / 4.3.7+
CRITICAL 9.8
CVE-2026-30831
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an…
Rocket.chat
7.10.8 / 7.11.5+
CRITICAL 9.8
CVE-2026-28514
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an…
Rocket.chat
7.8.6 / 7.9.8+
CRITICAL 9.8
CVE-2026-29075
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and pri…
Mesa
after 3.5.0
CRITICAL 9.8
CVE-2026-26288
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Api.everon.io
Mitigation only
CRITICAL 9.8
CVE-2026-26051
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Mobiliti E Mobi.hu
Mitigation only
CRITICAL 9.8
CVE-2018-25199
OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious …
Php Oop Cms Blog
Mitigation only
CRITICAL 9.8
CVE-2018-25187
Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection a…
Tina4 Stack
Mitigation only
CRITICAL 9.8
CVE-2026-2331
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to imprope…
Mitigation only
CRITICAL 9.4
CVE-2026-2330
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain direct…
Mitigation only
CRITICAL 9.1
CVE-2026-29065
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore func…
Changedetection
0.54.4+
CRITICAL 9.8
CVE-2026-29058
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj…
Avideo Encoder
7.0+
CRITICAL 9.8
CVE-2026-29042
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a …
Nuclio
1.15.20+
CRITICAL 9.8
CVE-2026-28802
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi…
Authlib
1.6.7+
CRITICAL 9.8
CVE-2026-28795
OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through n…
Openchatbi
0.2.2+
CRITICAL 9.8
CVE-2026-28438
CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name befo…
Cocoindex
0.3.34+
CRITICAL 9.8
CVE-2026-2446
The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated use…
Mitigation only
CRITICAL 9.8
CVE-2026-28794
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution v…
Orpc
1.13.6+
CRITICAL 9.0
CVE-2026-28787
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no…
Oneuptime
after 10.0.11
CRITICAL 9.8
CVE-2026-28785
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary …
Ghostfolio
2.244.0+
CRITICAL 9.3
CVE-2026-28680
Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform…
Ghostfolio
2.245.0+
CRITICAL 9.8
CVE-2026-27005
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3…
Chartbrew
4.8.3+