Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-27180
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning…
Majordomo
Patch available
CRITICAL 9.8
CVE-2026-27179
MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php fil…
Majordomo
Patch available
CRITICAL 9.8
CVE-2026-27175EPSS 7%
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is …
Majordomo
Patch available
CRITICAL 9.8
CVE-2026-27174EPSS 7%
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in…
Majordomo
Patch available
CRITICAL 9.8
CVE-2019-25365
ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by over…
Mitigation only
CRITICAL 9.8
CVE-2019-25364
MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers …
Mailcarrier
Mitigation only
CRITICAL 9.8
CVE-2019-25362
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting th…
Wmv To Avi Mpeg Dvd Wmv Convertor
Mitigation only
CRITICAL 9.8
CVE-2019-25361
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code.…
Mitigation only
CRITICAL 9.8
CVE-2019-25360
Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code b…
Aida64
Mitigation only
CRITICAL 9.0
CVE-2026-0573
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…
Enterprise Server
3.14.22 / 3.15.17+
CRITICAL 9.8
CVE-2025-70152
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.p…
Scholars Tracking System
Mitigation only
CRITICAL 9.8
CVE-2025-70150
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attacker…
Membership Management System
Mitigation only
CRITICAL 9.8
CVE-2025-70149
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
Membership Management System
Mitigation only
CRITICAL 9.1
CVE-2025-70146
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke…
Online Time Table Generator
No fix yet
CRITICAL 9.4
CVE-2025-70141
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…
Customer Support System
No fix yet
CRITICAL 9.8
CVE-2025-70998
UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowin…
810 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-65791
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…
Zoneminder
Mitigation only
CRITICAL 9.5
CVE-2025-15579
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.
The vulnerability could lead to remote cod…
Mitigation only
CRITICAL 9.8
CVE-2026-2329EPSS 40%
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage …
Gxp1610 Firmware
1.0.7.81+
CRITICAL 9.8
CVE-2026-2654
A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExec…
Smolagents
after 1.24.0
CRITICAL 9.8
CVE-2026-1435
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new…
Graylog
Mitigation only
CRITICAL 9.8
CVE-2026-1670
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password…
Mitigation only
CRITICAL 10.0
CVE-2026-22769 KEVEPSS 13%
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a…
Recoverpoint For Virtual Machines
6.0+
CRITICAL 9.8
CVE-2025-33089
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …
Concert
2.2.0+
CRITICAL 9.1
CVE-2025-66614
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…
Tomcat
9.0.113 / 10.1.50+
CRITICAL 9.9
CVE-2025-59793
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to uploa…
Trufusion Enterprise
7.10.5.0+
CRITICAL 9.8
CVE-2026-23647
Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication …
Mitigation only
CRITICAL 9.9
CVE-2025-70830
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execu…
Mitigation only
CRITICAL 9.8
CVE-2026-2616
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface…
777vr1 Firmware
after 01.00.09_55
CRITICAL 9.6
CVE-2026-22208
OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua i…
Patch available