Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 10.0
CVE-2026-28353
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed v…
Mitigation only
CRITICAL 9.8
CVE-2025-29165
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
Dir 1253 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-27944EPSS 22%
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and …
Nginx Ui
2.3.3+
CRITICAL 9.3
CVE-2026-25921
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack,…
Gogs
0.14.2+
CRITICAL 9.8
CVE-2026-24457
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's…
Openmq
after 6.5.1
CRITICAL 9.8
CVE-2025-70233
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70232
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70231
D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin…
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70230
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70229
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-13476
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking exte…
Viber
after 25.8.1.0
CRITICAL 9.8
CVE-2026-30793
Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR…
Rustdesk
after 1.4.5
CRITICAL 9.8
CVE-2026-30789
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-clie…
Rustdesk
after 1.4.5
CRITICAL 9.8
CVE-2026-30783
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop…
Rustdesk
after 1.4.5
CRITICAL 9.8
CVE-2026-2599
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…
Mitigation only
CRITICAL 9.8
CVE-2026-21628
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Astroid Framework
after 3.3.10
CRITICAL 9.8
CVE-2026-2743
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf…
Seppmail
after 15.0.2.1
CRITICAL 9.8
CVE-2026-25702
A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via…
Linux Enterprise Server
Mitigation only
CRITICAL 9.8
CVE-2026-1678
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, a…
Zephyr
after 4.3.0
CRITICAL 9.1
CVE-2026-2418
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticat…
Mitigation only
CRITICAL 10.0
CVE-2026-29128
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…
Sfx2100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-29053
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s…
Ghost
6.19.1+
CRITICAL 9.3
CVE-2026-28115
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy St…
Mitigation only
CRITICAL 9.1
CVE-2026-28114
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell …
Mitigation only
CRITICAL 9.8
CVE-2026-28105
Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a t…
Mitigation only
CRITICAL 9.8
CVE-2026-28074
Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a t…
Mitigation only
CRITICAL 9.8
CVE-2026-28043
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Cl…
Mitigation only
CRITICAL 9.0
CVE-2026-27984
Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is…
Mitigation only
CRITICAL 9.8
CVE-2026-27983
Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS E…
Mitigation only
CRITICAL 9.8
CVE-2026-27439
Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <…
Mitigation only