Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-28268
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password re…
Vikunja
2.1.0+
CRITICAL 9.1
CVE-2026-28231
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path bu…
Pillow Heif
1.3.0+
CRITICAL 9.8
CVE-2026-27707
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an au…
Seerr
3.1.0+
CRITICAL 9.1
CVE-2026-2880
A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example,…
Fastify\/middie
9.2.0+
CRITICAL 9.8
CVE-2026-27755
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge …
Sl902 Swtgw124as Firmware
after 200.1.20
CRITICAL 9.8
CVE-2026-27751
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain adminis…
Sl902 Swtgw124as Firmware
after 200.1.20
CRITICAL 9.1
CVE-2019-25489
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…
Airbnb Clone Script
No fix yet
CRITICAL 9.8
CVE-2026-2293
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio…
Nest
Mitigation only
CRITICAL 9.8
CVE-2026-2750
Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec…
Web
24.04.24 / 24.10.20+
CRITICAL 9.8
CVE-2026-2751
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…
Centreon Web
24.04.24. / 24.10.20+
CRITICAL 9.3
CVE-2025-15498
Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to b…
Mitigation only
CRITICAL 9.8
CVE-2025-11252
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. W…
Windesk.fm
after 27022026
CRITICAL 9.8
CVE-2026-24352
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…
Pluxml
Mitigation only
CRITICAL 9.8
CVE-2025-11251
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Comm…
Woyio
Mitigation only
CRITICAL 9.8
CVE-2026-21660
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD ve…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21659
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-2251
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal …
Freeflow Core
8.1.0+
CRITICAL 9.8
CVE-2026-21658
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21657
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21656
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21654
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.1
CVE-2026-1626
An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypt…
Lms1000 Firmware
2.4.1+
CRITICAL 9.8
CVE-2025-12981
The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation …
Mitigation only
CRITICAL 9.8
CVE-2026-3301
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …
N300rh Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-3289
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…
Publiccms
Mitigation only
CRITICAL 9.8
CVE-2026-3287
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m…
Youlai Mall
Mitigation only
CRITICAL 9.1
CVE-2026-28370
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code executi…
Vitrage
12.01 / 13.0.1+
CRITICAL 9.8
CVE-2026-24497
Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: from 7 throug…
Thinkwise
23+
CRITICAL 9.1
CVE-2026-22877
An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1
and prior, enabling unauthenticated attackers to read arbitrary files on
the…
Xweb 300d Pro Firmware
after 1.12.1
CRITICAL 9.8
CVE-2026-20797
A stack based buffer overflow exists in an API route of XWEB Pro version
1.12.1 and prior, enabling unauthenticated attackers to cause stack
corrup…
Xweb 300d Pro Firmware
after 1.12.1