Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 10.0
CVE-2026-27211
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (cons…
Cloud Hypervisor
50.1+
CRITICAL 9.1
CVE-2026-27197
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML…
Sentry
26.2.0+
CRITICAL 9.8
CVE-2026-27194
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter e…
D Tale
after 3.19.1
CRITICAL 9.8
CVE-2026-27168
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to…
Sail
after 0.9.10
CRITICAL 9.8
CVE-2026-2039
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio…
Archiver
Mitigation only
CRITICAL 9.8
CVE-2026-2038
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…
Archiver
Mitigation only
CRITICAL 9.8
CVE-2019-25441EPSS 8%
thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mal…
Thesystem
Mitigation only
CRITICAL 9.9
CVE-2026-27112
Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoi…
Kargo
1.7.8 / 1.8.11+
CRITICAL 9.8
CVE-2026-27190
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl…
Deno
2.6.8+
CRITICAL 9.3
CVE-2026-25896
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From…
Fast Xml Parser
5.3.5+
CRITICAL 10.0
CVE-2021-35402
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter…
Mitigation only
CRITICAL 9.1
CVE-2019-25444
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting S…
Fiverr Clone Script
No fix yet
CRITICAL 9.8
CVE-2026-2848
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file…
Simple Responsive Tourism Website
Mitigation only
CRITICAL 9.8
CVE-2026-2333
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ…
Opds Talon
Mitigation only
CRITICAL 9.1
CVE-2026-26747
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php…
Monica
No fix yet
CRITICAL 9.8
CVE-2026-26725
An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID p…
Print Shop Pro Webdesk
Mitigation only
CRITICAL 9.4
CVE-2026-26722
An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of th…
Global Facilities Management Software
No fix yet
CRITICAL 9.8
CVE-2026-26093
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ…
Opds Talon
Mitigation only
CRITICAL 9.8
CVE-2026-25715
The web management interface of the device allows the administrator
username and password to be set to blank values. Once applied, the
device permi…
Mitigation only
CRITICAL 9.4
CVE-2025-70833
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra…
Smanga
Mitigation only
CRITICAL 9.3
CVE-2026-24956
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor …
Mitigation only
CRITICAL 9.8
CVE-2026-22384
Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay …
Mitigation only
CRITICAL 9.8
CVE-2025-70831
A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly saniti…
Smanga
Mitigation only
CRITICAL 9.8
CVE-2025-69405
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.T…
Mitigation only
CRITICAL 9.8
CVE-2025-69404
Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from…
Mitigation only
CRITICAL 9.9
CVE-2025-69403
Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue af…
Mitigation only
CRITICAL 9.8
CVE-2025-69382
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Th…
Mitigation only
CRITICAL 9.8
CVE-2025-69372
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a…
Mitigation only
CRITICAL 9.8
CVE-2025-69371
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a…
Mitigation only
CRITICAL 9.8
CVE-2025-69370
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <=…
Mitigation only