Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-24770
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a …
Ragflow
after 0.23.1
CRITICAL 9.9
CVE-2026-24740
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict…
Dozzle
9.0.3+
CRITICAL 9.8
CVE-2025-21589
An Authentication Bypass Using an
Alternate Path or Channel vulnerability in Juniper Networks Session Smart
Router may allows a network-based attacke…
Mitigation only
CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…
Fortianalyzer
7.4.10 / 7.4.11+
CRITICAL 10.0
CVE-2025-14988
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the…
No fix yet
CRITICAL 9.8
CVE-2026-24881
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo…
Gnupg
2.5.17 / 5.0.1+
CRITICAL 9.1
CVE-2026-22264
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free cond…
Suricata
7.0.14 / 8.0.3+
CRITICAL 9.8
CVE-2026-22262
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,…
Suricata
7.0.14 / 8.0.3+
CRITICAL 9.9
CVE-2026-22039
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…
Kyverno
1.15.3 / 1.16.3+
CRITICAL 9.8
CVE-2025-69564
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,…
Mobile Shop Management System
Mitigation only
CRITICAL 9.8
CVE-2025-69563
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.
Mobile Shop Management System
Mitigation only
CRITICAL 9.8
CVE-2025-69562
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.
Mobile Shop Management System
Mitigation only
CRITICAL 9.8
CVE-2025-69559
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
Computer Book Store
Mitigation only
CRITICAL 9.1
CVE-2026-24874
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before …
Xray Monolith
2025.12.30+
CRITICAL 9.8
CVE-2026-24872
improper pointer arithmetic
vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.
Patch available
CRITICAL 10.0
CVE-2026-24871
Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Mana…
Patch available
CRITICAL 9.8
CVE-2026-24832
Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
Ix Ray Engine 1.6
1.3+
CRITICAL 9.8
CVE-2025-69565
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
Mobile Shop Management System
Mitigation only
CRITICAL 9.8
CVE-2025-68670
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im…
Debian Linux
0.10.5+
CRITICAL 9.8
CVE-2021-47901
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected e…
Mitigation only
CRITICAL 9.8
CVE-2021-47900
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comm…
Mitigation only
CRITICAL 9.8
CVE-2020-36948
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attac…
Mitigation only
CRITICAL 9.8
CVE-2020-36941
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server he…
Knockpy
Mitigation only
CRITICAL 9.8
CVE-2020-36940
Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the applica…
Mitigation only
CRITICAL 9.9
CVE-2026-1470EPSS 19%
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated…
N8n
1.123.17 / 2.4.5+
CRITICAL 9.8
CVE-2026-24830
Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.
Patch available
CRITICAL 10.0
CVE-2026-24826
Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i…
Patch available
CRITICAL 9.1
CVE-2026-24346
Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web applicat…
Ezcast Pro Dongle Ii Firmware
Mitigation only
CRITICAL 10.0
CVE-2026-24823
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER…
Patch available
CRITICAL 10.0
CVE-2026-24822
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files…
Patch available