Top technology
Linux 13139
Google 12755
Microsoft 12400
Oracle 7431
Apple 6696
Ibm 6475
Adobe 6419
Cisco 5766
Debian 3920
Apache 2915
Mozilla 2912
Redhat 2623
CRITICAL 9.8
CVE-2025-69762
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote …
Ax3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-47875
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buf…
Mitigation only
CRITICAL 9.8
CVE-2021-47854
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execu…
Mitigation only
CRITICAL 9.8
CVE-2021-47851
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP e…
Mini Mouse
Mitigation only
CRITICAL 9.8
CVE-2021-47748
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip…
Graphql Engine
Mitigation only
CRITICAL 9.8
CVE-2026-20045 KEV
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…
Unified Communications Manager
14su5+
CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Debian Linux
after 2.7
CRITICAL 9.8
CVE-2025-15521
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeove…
Mitigation only
CRITICAL 9.9
CVE-2026-0933
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…
Wrangler
3.114.17 / 4.59.1+
CRITICAL 9.8
CVE-2026-21969
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The support…
Agile Product Lifecycle Management For Process
Mitigation only
CRITICAL 10.0
CVE-2026-21962 KEVEPSS 42%
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy P…
HTTP Server
Patch available
CRITICAL 10.0
CVE-2026-21636
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …
Node.js
25.3.0+
CRITICAL 9.1
CVE-2025-55130
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink…
Node.js
20.20.0 / 22.22.0+
CRITICAL 9.8
CVE-2025-56005EPSS 17%
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the…
Ply
No fix yet
CRITICAL 9.8
CVE-2025-55423
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port…
N104s R1 Firmware
after 12.07.6
CRITICAL 9.8
CVE-2025-65482
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a craft…
Xdocreport
after 2.0.3
CRITICAL 9.8
CVE-2025-64087
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execu…
Xdocreport
after 2.1.0
CRITICAL 9.8
CVE-2025-36418
IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra…
Applinx
Mitigation only
CRITICAL 9.9
CVE-2026-22844EPSS 13%
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote …
Mitigation only
CRITICAL 9.8
CVE-2025-14533
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i…
Mitigation only
CRITICAL 9.8
CVE-2026-1221
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote att…
Mitigation only
CRITICAL 9.8
CVE-2026-0907EPSS 8%
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.…
Chrome
144.0.7559.59 / 144.0.7559.60+
CRITICAL 9.8
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi…
Chrome
144.0.7559.59 / 144.0.7559.60+
CRITICAL 9.8
CVE-2026-0905
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o…
Chrome
144.0.7559.59 / 144.0.7559.60+
CRITICAL 9.8
CVE-2026-23947
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…
Orval
7.19.0 / 8.0.2+
CRITICAL 9.8
CVE-2026-23876
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffe…
Imagemagick
6.9.13-38 / 7.1.2-13+
CRITICAL 9.8
CVE-2026-22770
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of d…
Imagemagick
7.1.2-13+
CRITICAL 9.8
CVE-2026-1202
A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log…
Crmeb
after 5.6.3
CRITICAL 9.8
CVE-2026-1179
A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H…
Ksoa
Mitigation only
CRITICAL 9.8
CVE-2026-23944
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox…
Arcane
1.13.2+