Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-26002
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible…
Open Ondemand
3.1.16 / 4.0.9+
CRITICAL 9.1
CVE-2026-29000EPSS 6%
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs…
Mitigation only
CRITICAL 9.8
CVE-2025-70222
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.
Dir 513 Firmware
Mitigation only
CRITICAL 9.0
CVE-2025-66024
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vu…
Blog Application
9.15.7+
CRITICAL 9.8
CVE-2025-70225
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70221
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-46108
D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.
Dir 513 Firmware
Mitigation only
CRITICAL 9.6
CVE-2026-3545
Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape…
Chrome
145.0.7632.159 / 145.0.7632.160+
CRITICAL 9.8
CVE-2025-70219
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70226
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70223
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.
Dir 513 Firmware
Mitigation only
CRITICAL 10.0
CVE-2026-20131 KEVEPSS 31%
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot…
Secure Firewall Management Center
Mitigation only
CRITICAL 10.0
CVE-2026-20079EPSS 36%
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to byp…
Mitigation only
CRITICAL 9.8
CVE-2025-70220
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-70218
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.
Dir 513 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-25506
FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass au…
Freesms
after 2.1.2
CRITICAL 9.8
CVE-2019-25499
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …
Simplejobscript
after 1.66
CRITICAL 9.1
CVE-2026-28783
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou…
Craft Cms
4.17.0 / 5.9.0+
CRITICAL 9.1
CVE-2026-28697
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution…
Craft Cms
4.17.0 / 5.9.0+
CRITICAL 9.6
CVE-2025-69969
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism …
Pebble Prism Ultra Firmware
2.5.8+
CRITICAL 9.8
CVE-2025-66944
SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in t…
Databasir
after 1.0.7
CRITICAL 9.8
CVE-2025-66678
An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitr…
Hardware Read \& Write Utility
after 1.25.11.26
CRITICAL 9.8
CVE-2026-26478
A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf…
Tichome Mini Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-59786
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in…
Access Commander
3.5+
CRITICAL 9.8
CVE-2026-27446EPSS 10%
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…
Artemis
after 2.44.0
CRITICAL 9.8
CVE-2026-27441
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
Seppmail
15.0.1+
CRITICAL 9.8
CVE-2026-29119
International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…
Sfx2100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-28778
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd…
Sfx2100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-28777
International Datacasting Corporation (IDC)
SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated att…
Sfx2100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-28776
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote…
Sfx2100 Firmware
Mitigation only