Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.2
CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a de…
Mitigation only
CRITICAL 9.8
CVE-2026-25526
JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJav…
Jinjava
2.7.6 / 2.8.3+
CRITICAL 9.8
CVE-2026-25519
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to v…
Openslides
4.2.29+
CRITICAL 9.8
CVE-2025-13375
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privile…
Mitigation only
CRITICAL 9.8
CVE-2026-25505
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign…
Bambuddy
0.1.7+
CRITICAL 9.6
CVE-2026-25481
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-4…
Langroid
0.59.32+
CRITICAL 9.1
CVE-2026-25139
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…
Riot
after 2025.10
CRITICAL 9.1
CVE-2026-22247
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through …
Glpi
11.0.5+
CRITICAL 9.8
CVE-2025-64712
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a…
Unstructured
0.18.18+
CRITICAL 9.9
CVE-2026-25115
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to bre…
N8n
2.4.8+
CRITICAL 9.9
CVE-2026-25053
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users…
N8n
1.123.0 / 2.5.0+
CRITICAL 9.9
CVE-2026-25052
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenti…
N8n
1.123.18 / 2.5.0+
CRITICAL 9.9
CVE-2026-25049
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify w…
N8n
1.123.17 / 2.5.2+
CRITICAL 9.8
CVE-2025-5329
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation …
Mitigation only
CRITICAL 9.8
CVE-2025-59818
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
Tcis 3 Firmware
9.2.3.3+
CRITICAL 9.8
CVE-2026-1813
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp…
Bolo Solo
after 2.6.4
CRITICAL 10.0
CVE-2026-1633
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent…
Mitigation only
CRITICAL 9.8
CVE-2026-1812
A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/so…
Bolo Solo
after 2.6.4
CRITICAL 9.1
CVE-2026-1632
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen…
Mitigation only
CRITICAL 10.0
CVE-2026-25150
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function w…
Qwik
1.19.0+
CRITICAL 9.3
CVE-2026-1341
Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
Mitigation only
CRITICAL 9.8
CVE-2020-37090
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl…
School Erp Pro
Mitigation only
CRITICAL 9.8
CVE-2020-37089
School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu…
School Erp Pro
Mitigation only
CRITICAL 9.8
CVE-2020-37080
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delet…
Mitigation only
CRITICAL 9.8
CVE-2020-37075
LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute ar…
Mitigation only
CRITICAL 9.8
CVE-2020-37074
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wiza…
Mitigation only
CRITICAL 9.8
CVE-2020-37071
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a …
Mitigation only
CRITICAL 9.8
CVE-2020-37070
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attac…
Mitigation only
CRITICAL 9.8
CVE-2020-37069
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Atta…
Ftp Utility
Mitigation only
CRITICAL 9.8
CVE-2020-37068
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Atta…
Ftp Utility
Mitigation only