Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-0770 KEVEPSS 63%
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote …
Langflow
after 1.7.3
CRITICAL 9.8
CVE-2026-0769EPSS 38%
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…
Langflow
Mitigation only
CRITICAL 9.8
CVE-2026-0768
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
Langflow
Mitigation only
CRITICAL 9.8
CVE-2026-0764
GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…
Gpt Academic
Mitigation only
CRITICAL 9.8
CVE-2026-0763
GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…
Gpt Academic
Mitigation only
CRITICAL 9.8
CVE-2026-0761
Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers …
Metagpt
Mitigation only
CRITICAL 9.8
CVE-2026-0760
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote…
Metagpt
Mitigation only
CRITICAL 9.8
CVE-2026-0759
Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…
Mitigation only
CRITICAL 9.8
CVE-2026-0756
github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…
Mitigation only
CRITICAL 9.8
CVE-2026-0755
gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…
Mitigation only
CRITICAL 9.8
CVE-2025-15063
Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…
Mitigation only
CRITICAL 9.8
CVE-2025-15061
Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…
Mitigation only
CRITICAL 9.9
CVE-2026-24304
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Azure Resource Manager
Mitigation only
CRITICAL 9.8
CVE-2026-24132
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions
7.19.0 and below and 8.0.0-rc.0 th…
Orval
7.20.0 / 8.0.3+
CRITICAL 9.8
CVE-2026-24306
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-24305
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2026-24124
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…
Dragonfly
2.4.1+
CRITICAL 9.8
CVE-2026-21227
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
Azure Logic Apps
Mitigation only
CRITICAL 9.8
CVE-2025-55705
This vulnerability occurs when the system permits multiple simultaneous
connections to the backend using the same charging station ID. This can
res…
Evmapa
Mitigation only
CRITICAL 9.8
CVE-2025-54816
This vulnerability occurs when a WebSocket endpoint does not enforce
proper authentication mechanisms, allowing unauthorized users to
establish con…
Evmapa
Mitigation only
CRITICAL 9.8
CVE-2026-24058
Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that all…
Soft Serve
0.11.3+
CRITICAL 9.1
CVE-2026-20912
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…
Gitea
1.25.4+
CRITICAL 9.1
CVE-2026-20897
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…
Gitea
1.25.4+
CRITICAL 9.1
CVE-2026-20750
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab…
Gitea
1.25.4+
CRITICAL 9.4
CVE-2026-1201
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could a…
Mitigation only
CRITICAL 9.8
CVE-2025-56590
An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute …
Html2pdf
Mitigation only
CRITICAL 9.8
CVE-2026-22278
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthentica…
Powerscale Onefs
9.13.0.0+
CRITICAL 10.0
CVE-2025-69828
File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via…
Mitigation only
CRITICAL 9.1
CVE-2025-69312
Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web …
Mitigation only
CRITICAL 9.8
CVE-2025-69101
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This iss…
Mitigation only