Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-49457
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak…
No fix yet
CRITICAL 10.0
CVE-2026-19188
A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net…
No fix yet
CRITICAL 9.8
CVE-2026-73849
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately …
No fix yet
CRITICAL 9.8
CVE-2026-48528
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth…
No fix yet
CRITICAL 9.9
CVE-2026-19682
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…
Security Center
6.9.0+
CRITICAL 9.9
CVE-2026-19681
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…
Security Center
6.9.0+
CRITICAL 9.9
CVE-2026-19626
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …
Security Center
6.9.0+
CRITICAL 9.3
CVE-2026-19871
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a…
Patch available
CRITICAL 9.8
CVE-2026-72830
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu…
No fix yet
CRITICAL 9.8
CVE-2026-72829
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. …
No fix yet
CRITICAL 9.8
CVE-2026-72826
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in …
No fix yet
CRITICAL 9.8
CVE-2026-72824
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-tog…
No fix yet
CRITICAL 9.8
CVE-2026-72822
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik…
No fix yet
CRITICAL 10.0
CVE-2026-72811
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates s…
No fix yet
CRITICAL 9.8
CVE-2026-12949
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and i…
No fix yet
CRITICAL 9.6
CVE-2026-73843
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f…
Patch available
CRITICAL 9.0
CVE-2026-73842
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex…
Patch available
CRITICAL 9.3
CVE-2026-73665
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke…
No fix yet
CRITICAL 9.3
CVE-2026-73663
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted …
Patch available
CRITICAL 9.1
CVE-2026-73421
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for …
Patch available
CRITICAL 9.1
CVE-2026-73420
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by th…
Patch available
CRITICAL 9.0
CVE-2026-73302
Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a…
Patch available
CRITICAL 10.0
CVE-2026-72851
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c…
No fix yet
CRITICAL 9.1
CVE-2026-72850
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p…
No fix yet
CRITICAL 9.9
CVE-2026-72842
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management r…
No fix yet
CRITICAL 9.9
CVE-2026-72841
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal a…
No fix yet
CRITICAL 9.8
CVE-2026-72839
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen…
No fix yet
CRITICAL 9.8
CVE-2026-72776
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb…
Patch available
CRITICAL 9.6
CVE-2026-8715
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication conf…
No fix yet
CRITICAL 9.1
CVE-2026-19297
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of exce…
No fix yet