Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-29093
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…
Avideo
24.0+
CRITICAL 9.8
CVE-2026-28501
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec…
Avideo
24.0+
CRITICAL 9.1
CVE-2026-28497
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer …
Tinyweb
2.03+
CRITICAL 9.0
CVE-2025-59543
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious…
Chamilo Lms
1.11.34+
CRITICAL 9.0
CVE-2025-59542
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious…
Chamilo Lms
1.11.34+
CRITICAL 9.0
CVE-2025-55289
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an att…
Chamilo Lms
1.11.34+
CRITICAL 9.8
CVE-2026-28710
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linu…
Cyber Protect
17.0.41186+
CRITICAL 9.8
CVE-2026-22552
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Epower.ie
Mitigation only
CRITICAL 9.8
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service
No fix yet
CRITICAL 9.8
CVE-2026-21536
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Devices Pricing Program
No fix yet
CRITICAL 9.1
CVE-2026-28479
OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecat…
Openclaw
2026.2.15+
CRITICAL 9.8
CVE-2026-28474
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid…
Openclaw
2026.2.6+
CRITICAL 9.8
CVE-2026-28472
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch…
Openclaw
2026.2.2+
CRITICAL 9.8
CVE-2026-28470
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit…
Openclaw
2026.2.2+
CRITICAL 9.9
CVE-2026-28466
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…
Openclaw
2026.2.14+
CRITICAL 9.1
CVE-2026-28462
OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and …
Openclaw
2026.2.13+
CRITICAL 9.8
CVE-2026-28454
OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST r…
Openclaw
2026.2.2+
CRITICAL 9.8
CVE-2026-28453
OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out…
Openclaw
2026.2.14+
CRITICAL 9.3
CVE-2026-28451
OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack…
Openclaw
2026.2.14+
CRITICAL 9.4
CVE-2026-28448
OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor…
Openclaw
2026.2.1+
CRITICAL 9.8
CVE-2026-28446
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound all…
Openclaw
2026.2.2+
CRITICAL 9.1
CVE-2026-28395
OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and ena…
Openclaw
2026.2.12+
CRITICAL 9.8
CVE-2026-28393
OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc…
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2026-28392
OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any …
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2026-28391
OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat…
Openclaw
2026.2.2+
CRITICAL 9.8
CVE-2026-21622
Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover.
Password …
Hexpm
2026-03-05+
CRITICAL 9.8
CVE-2026-28443
OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sor…
Openreplay
1.20.0+
CRITICAL 10.0
CVE-2026-0848
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamic…
Nltk
after 3.9.2
CRITICAL 9.3
CVE-2025-70948
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an a…
Mitigation only
CRITICAL 9.0
CVE-2025-55208
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, …
Chamilo Lms
1.11.34+