Top technology
Linux 13139
Google 12755
Microsoft 12400
Oracle 7431
Apple 6696
Ibm 6475
Adobe 6419
Cisco 5766
Debian 3920
Apache 2915
Mozilla 2912
Redhat 2623
CRITICAL 9.9
CVE-2025-67968
Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a…
Mitigation only
CRITICAL 9.3
CVE-2025-67945
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration…
Mitigation only
CRITICAL 9.1
CVE-2025-67944
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi…
Mitigation only
CRITICAL 9.8
CVE-2025-67617
Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t…
Mitigation only
CRITICAL 9.9
CVE-2025-62056
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=…
Mitigation only
CRITICAL 9.9
CVE-2025-62050
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.…
Mitigation only
CRITICAL 10.0
CVE-2025-50002
Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects …
Mitigation only
CRITICAL 9.3
CVE-2025-49055
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca…
Mitigation only
CRITICAL 9.8
CVE-2026-24009
Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML…
Docling Core
2.48.4+
CRITICAL 9.8
CVE-2025-69764
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buff…
Ax3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-23760 KEVEPSS 96%
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw…
Smartermail
100.0.9511+
CRITICAL 9.8
CVE-2026-1325
A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_…
Operation And Maintenance Security Management System
after 3.0.12
CRITICAL 9.8
CVE-2026-1324EPSS 7%
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon…
Operation And Maintenance Security Management System
after 3.0.12
CRITICAL 9.8
CVE-2025-64097
NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting …
Nerveshub
2.3.0+
CRITICAL 9.8
CVE-2026-1331
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu…
Meetinghub Paperless Meetings
2025-12-10+
CRITICAL 9.8
CVE-2026-0920
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.…
Mitigation only
CRITICAL 9.8
CVE-2026-24042
Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica…
Appsmith
after 1.94
CRITICAL 9.6
CVE-2026-24002
Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases w…
Grist Core
1.7.9+
CRITICAL 9.1
CVE-2026-23966
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists …
Sm Crypto
0.3.14+
CRITICAL 9.8
CVE-2026-23958
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT s…
Dataease
2.10.19+
CRITICAL 9.8
CVE-2025-27378
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …
On Prem Enterprise Server
7.0.6+
CRITICAL 9.0
CVE-2026-23873
hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Form…
Hustoj
after 26.01.31
CRITICAL 9.8
CVE-2026-23736
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to im…
Seroval
1.4.1+
CRITICAL 9.8
CVE-2026-23524
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th…
Reverb
1.7.0+
CRITICAL 9.8
CVE-2026-23518
Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows …
Fleet
4.53.3 / 4.75.2+
CRITICAL 9.8
CVE-2026-22807
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging …
Vllm
0.14.0+
CRITICAL 9.6
CVE-2026-22793
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsi…
5ire
0.15.3+
CRITICAL 9.6
CVE-2026-22792
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML renderi…
5ire
0.15.3+
CRITICAL 9.8
CVE-2025-69766
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buff…
Ax3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-69763
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remot…
Ax3 Firmware
Mitigation only