Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-24465
Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.
Wab S300iw Pd Firmware
1.13 / 5.5.02+
CRITICAL 9.8
CVE-2026-24936
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…
Data Master
5.1.2.re51+
CRITICAL 9.8
CVE-2025-67484
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php.
This issue affec…
Mediawiki
1.39.16 / 1.43.6+
CRITICAL 10.0
CVE-2026-25142
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain proto…
Sandboxjs
0.8.27+
CRITICAL 9.1
CVE-2026-25137EPSS 10%
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the …
Patch available
CRITICAL 9.3
CVE-2026-24471
continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server t…
No fix yet
CRITICAL 9.0
CVE-2026-23997
FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulne…
Facturascripts
2025.71+
CRITICAL 9.8
CVE-2026-22778
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim…
Vllm
0.14.1+
CRITICAL 9.8
CVE-2025-66480
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re…
Im Server
1.4.3+
CRITICAL 9.8
CVE-2022-50981
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is …
Mitigation only
CRITICAL 9.8
CVE-2025-8587
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade…
Skspro
after 2026-07-01
CRITICAL 9.1
CVE-2024-5986
A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploi…
Mitigation only
CRITICAL 9.6
CVE-2024-2356
A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically withi…
Patch available
CRITICAL 9.8
CVE-2026-20418
In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additiona…
Matter
after 1.4
CRITICAL 9.3
CVE-2026-20407
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with …
Nbiot Sdk
after 3.8
CRITICAL 9.8
CVE-2025-15030
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re…
Mitigation only
CRITICAL 9.8
CVE-2026-25202
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M…
Magicinfo 9 Server
21.1090.1+
CRITICAL 9.8
CVE-2026-25200
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in …
Magicinfo 9 Server
21.1090.1+
CRITICAL 9.8
CVE-2026-1740
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo…
A8004t Firmware
Mitigation only
CRITICAL 9.3
CVE-2026-25069
SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth…
Mitigation only
CRITICAL 9.8
CVE-2020-37057
Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through th…
Online Exam System
Mitigation only
CRITICAL 9.8
CVE-2020-37056
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating reque…
Mitigation only
CRITICAL 9.8
CVE-2020-37052
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system …
Mitigation only
CRITICAL 9.8
CVE-2020-37050
Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with care…
Mitigation only
CRITICAL 9.8
CVE-2020-37043
10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through c…
Mitigation only
CRITICAL 9.8
CVE-2020-37027
Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext…
Mitigation only
CRITICAL 9.8
CVE-2019-25232
NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary she…
Mitigation only
CRITICAL 9.8
CVE-2026-25141
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7…
Orval
7.21.0 / 8.2.0+
CRITICAL 9.6
CVE-2026-25130
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple…
Patch available
CRITICAL 9.2
CVE-2026-1723
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…
Mitigation only