Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2025-70085
An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Sou…
Opensatkit
Mitigation only
CRITICAL 9.8
CVE-2025-69874
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outsi…
Nanotar
after 0.2.0
CRITICAL 9.8
CVE-2026-25084
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
Mitigation only
CRITICAL 9.8
CVE-2026-24789
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Mitigation only
CRITICAL 10.0
CVE-2025-64075
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass au…
Mitigation only
CRITICAL 9.8
CVE-2026-2249
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …
Mitigation only
CRITICAL 9.8
CVE-2026-2248
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …
Mitigation only
CRITICAL 9.8
CVE-2025-12059
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platfor…
Mitigation only
CRITICAL 9.4
CVE-2025-8668
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering D…
Mitigation only
CRITICAL 9.8
CVE-2025-8025
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func…
Mitigation only
CRITICAL 9.8
CVE-2025-66277
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…
Qts
Mitigation only
CRITICAL 9.1
CVE-2025-7659
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could …
GitLab
18.6.6 / 18.7.4+
CRITICAL 9.8
CVE-2026-1357EPSS 33%
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u…
Mitigation only
CRITICAL 9.9
CVE-2026-26009
Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server te…
Patch available
CRITICAL 9.8
CVE-2026-25993
EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds
path / request_path val…
Evershop
after 2.1.0
CRITICAL 9.8
CVE-2026-21531
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Azure Conversation Authoring Client Library
Mitigation only
CRITICAL 9.8
CVE-2026-1774
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Mitigation only
CRITICAL 9.6
CVE-2025-52436EPSS 6%
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…
Fortisandbox
4.4.8 / 5.0.2+
CRITICAL 9.8
CVE-2026-23906
Affected Products and Versions
* Apache Druid
* Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
* Prerequisites: * d…
Druid
36.0.0+
CRITICAL 9.8
CVE-2025-11242
Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Si…
No fix yet
CRITICAL 9.8
CVE-2026-2096
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete dat…
Agentflow
Mitigation only
CRITICAL 9.8
CVE-2026-2095
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functiona…
Agentflow
Mitigation only
CRITICAL 9.6
CVE-2026-0509
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…
Netweaver As Abap Kernel
Mitigation only
CRITICAL 9.9
CVE-2026-0488
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.1
CVE-2026-25939EPSS 11%
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10,
an authorization bypass vulnerability i…
Fuxa
1.2.11+
CRITICAL 9.8
CVE-2026-25938
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…
Fuxa
1.2.11+
CRITICAL 9.8
CVE-2026-25895EPSS 11%
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at…
Fuxa
1.2.10+
CRITICAL 9.8
CVE-2026-25894
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote…
Fuxa
1.2.10+
CRITICAL 9.8
CVE-2026-25893
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…
Fuxa
1.2.10+
CRITICAL 9.1
CVE-2026-25923
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f…
My Little Forum
20260208.1+