Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-2624
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows…
Antikor Next Generation Firewall
2.0.1301+
CRITICAL 9.1
CVE-2026-0704
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va…
Octopus Server
2025.3.14715+
CRITICAL 9.9
CVE-2025-62878
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriti…
Mitigation only
CRITICAL 9.8
CVE-2026-3164
A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m…
News Portal Project
Mitigation only
CRITICAL 9.8
CVE-2026-3153
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipu…
Document Management System
Mitigation only
CRITICAL 9.8
CVE-2026-3152
A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php…
College Management System
Mitigation only
CRITICAL 9.8
CVE-2026-3151
A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The…
College Management System
Mitigation only
CRITICAL 9.8
CVE-2026-25785
Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke…
Lanscope Endpoint Manager
9.4.8.0+
CRITICAL 9.8
CVE-2026-3148
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. …
Simple And Nice Shopping Cart Script
Mitigation only
CRITICAL 9.8
CVE-2026-27744
The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for publ…
Tickets
4.3.3+
CRITICAL 9.8
CVE-2026-27743
The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_s…
Referer Spam
1.3.0+
CRITICAL 9.8
CVE-2026-27641
Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo…
Flask Reuploaded
1.5.0+
CRITICAL 9.8
CVE-2026-27637
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses …
Freescout
1.8.206+
CRITICAL 10.0
CVE-2026-27597
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boun…
Enclave
2.11.1+
CRITICAL 9.9
CVE-2026-27626
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…
Olivetin
after 3000.10.0
CRITICAL 9.1
CVE-2026-27607
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…
Rustfs
Mitigation only
CRITICAL 9.8
CVE-2026-27606
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i…
Rollup
2.80.0 / 3.30.0+
CRITICAL 9.8
CVE-2026-3135
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.p…
News Portal Project
Mitigation only
CRITICAL 9.8
CVE-2026-3134
A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admi…
News Portal Project
Mitigation only
CRITICAL 9.8
CVE-2026-3133
A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of …
Document Management System
Mitigation only
CRITICAL 9.8
CVE-2026-22553
All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that…
Masterscada
Mitigation only
CRITICAL 9.8
CVE-2026-21410
InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potenti…
Masterscada
Mitigation only
CRITICAL 9.8
CVE-2026-26342
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficien…
Smart\+ Firmware
after 1.181.5
CRITICAL 9.8
CVE-2026-26341
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed d…
Smart\+ Firmware
after 1.181.5
CRITICAL 9.8
CVE-2026-26222
Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH…
Altec Doclink
Mitigation only
CRITICAL 9.8
CVE-2026-27590
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…
Caddy
2.11.1+
CRITICAL 9.1
CVE-2026-27588
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i…
Caddy
2.11.1+
CRITICAL 9.1
CVE-2026-27587
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-…
Caddy
2.11.1+
CRITICAL 9.1
CVE-2026-27586
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` …
Caddy
2.11.1+
CRITICAL 9.1
CVE-2026-27515
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web managemen…
10g08 0800gsm Firmware
Mitigation only