Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.1
CVE-2026-27812
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior t…
Sub2api
0.1.85+
CRITICAL 9.1
CVE-2026-27809
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed …
Psd Tools
1.12.2+
CRITICAL 9.1
CVE-2026-27804
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an…
Parse Server
8.6.3 / 9.3.1+
CRITICAL 9.8
CVE-2026-27613
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers …
Tinyweb
2.01+
CRITICAL 9.9
CVE-2026-27577EPSS 10%
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation o…
N8n
1.123.22 / 2.9.3+
CRITICAL 9.9
CVE-2026-27495
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…
N8n
1.123.22 / 2.9.3+
CRITICAL 9.9
CVE-2026-27494
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…
N8n
1.123.22 / 2.9.3+
CRITICAL 9.0
CVE-2026-27493
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability …
N8n
1.123.22 / 2.9.3+
CRITICAL 9.1
CVE-2026-27575
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 123…
Vikunja
2.0.0+
CRITICAL 9.6
CVE-2026-27148
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10…
Storybook
7.6.23 / 8.6.17+
CRITICAL 9.8
CVE-2026-25997
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` m…
Freerdp
3.23.0+
CRITICAL 9.8
CVE-2026-25959
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XCha…
Freerdp
3.23.0+
CRITICAL 9.8
CVE-2026-25955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` wh…
Freerdp
3.23.0+
CRITICAL 9.8
CVE-2026-25953
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWi…
Freerdp
3.23.0+
CRITICAL 9.8
CVE-2026-25952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow`…
Freerdp
3.23.0+
CRITICAL 9.2
CVE-2026-0542
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an…
Mitigation only
CRITICAL 9.0
CVE-2026-22720
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be abl…
Aria Operations
5.2.3 / 8.18.6+
CRITICAL 9.2
CVE-2026-27739
The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-S…
Patch available
CRITICAL 9.8
CVE-2026-21902EPSS 18%
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved…
Junos Os Evolved
Mitigation only
CRITICAL 9.8
CVE-2026-27849
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall…
Mitigation only
CRITICAL 9.8
CVE-2026-27727
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo…
Mchange Commons Java
0.4.0+
CRITICAL 9.8
CVE-2026-20129
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 9.8
CVE-2026-27848
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as…
Mitigation only
CRITICAL 9.8
CVE-2026-27847
Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inj…
Mitigation only
CRITICAL 9.0
CVE-2026-27702
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…
Budibase
3.30.4+
CRITICAL 9.6
CVE-2025-69771
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut…
Asbplayer
after 1.13.0
CRITICAL 9.1
CVE-2025-1242
The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware revers…
Mitigation only
CRITICAL 9.8
CVE-2026-3187
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api…
Sz Boot Parent
after 0.9.0
CRITICAL 9.8
CVE-2026-27699
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m…
Basic Ftp
5.2.0+