Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-24114
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24113
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value …
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24111
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInf…
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24109
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this val…
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24108
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value …
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24107
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`…
W20e Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-23600
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
Autopass License Server
9.19+
CRITICAL 9.8
CVE-2025-50192
Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soa…
Chamilo Lms
1.11.30+
CRITICAL 9.8
CVE-2025-50190
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter wi…
Chamilo Lms
1.11.30+
CRITICAL 9.8
CVE-2025-50187
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote C…
Chamilo Lms
1.11.28+
CRITICAL 9.1
CVE-2026-3432
On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided …
Sim
0.5.74+
CRITICAL 9.8
CVE-2026-3431
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos…
Sim
0.5.74+
CRITICAL 9.8
CVE-2025-14532
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c…
Dorbycms
after 5.0
CRITICAL 9.3
CVE-2025-12462
A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in…
Mitigation only
CRITICAL 9.4
CVE-2025-30044
In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlo…
Mitigation only
CRITICAL 9.0
CVE-2025-30035
The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the…
Mitigation only
CRITICAL 9.3
CVE-2026-2584
A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthenticated, remote attacker (AV…
Mitigation only
CRITICAL 9.8
CVE-2026-3422
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary…
U Office Force
29.50+
CRITICAL 9.8
CVE-2026-3413
A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php…
University Management System
Mitigation only
CRITICAL 9.8
CVE-2026-3000
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the …
Idexpert
after 2.8.4.250925
CRITICAL 9.8
CVE-2026-2999
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the …
Idexpert
after 2.8.4.250925
CRITICAL 9.8
CVE-2026-3411
A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of …
University Management System
Mitigation only
CRITICAL 9.8
CVE-2026-3410
A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …
Society Management System
Mitigation only
CRITICAL 9.8
CVE-2026-3406
A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p…
Online Art Gallery Shop
Mitigation only
CRITICAL 9.8
CVE-2026-3400
A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEdi…
Ac15 Firmware
after 15.13.07.13
CRITICAL 9.8
CVE-2026-3395
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…
Maxsite Cms
109.2+
CRITICAL 9.8
CVE-2026-28562
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql…
Wpforo Forum
2.4.15+
CRITICAL 9.8
CVE-2026-28517EPSS 6%
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves …
Opendcim
Patch available
CRITICAL 9.8
CVE-2026-28411
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal …
Wegia
3.6.5+
CRITICAL 9.8
CVE-2026-28408
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…
Wegia
3.6.5+