Top technology
Linux 13139
Google 12755
Microsoft 12400
Oracle 7431
Apple 6696
Ibm 6475
Adobe 6419
Cisco 5766
Debian 3920
Apache 2915
Mozilla 2912
Redhat 2623
CRITICAL 9.8
CVE-2026-1125EPSS 15%
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.…
Dir 823x Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-1124
A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report…
Ksoa
Mitigation only
CRITICAL 9.9
CVE-2026-0863EPSS 9%
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted…
N8n
after 2.4.2
CRITICAL 9.8
CVE-2026-1123
A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Para…
Ksoa
Mitigation only
CRITICAL 9.8
CVE-2026-1122
A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Pa…
Ksoa
Mitigation only
CRITICAL 9.8
CVE-2026-1121
A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Para…
Ksoa
Mitigation only
CRITICAL 9.8
CVE-2026-1120
A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component H…
Ksoa
Mitigation only
CRITICAL 9.8
CVE-2026-1119
A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.p…
Society Management System
Mitigation only
CRITICAL 9.8
CVE-2026-1118
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/add_activity.php. Perf…
Society Management System
Mitigation only
CRITICAL 9.8
CVE-2026-1107
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…
Eyoucms
Mitigation only
CRITICAL 9.8
CVE-2026-1105
A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of …
Easycms
after 1.6
CRITICAL 9.8
CVE-2026-1062
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.…
Teamwork Management System
after 2.28.0
CRITICAL 9.8
CVE-2026-1061
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/…
Teamwork Management System
after 2.28.0
CRITICAL 9.8
CVE-2026-1059
A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknow…
Warehouse Management System
after 2021-11-15
CRITICAL 9.8
CVE-2025-10484
The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, …
Mitigation only
CRITICAL 9.8
CVE-2025-15403
The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a…
Mitigation only
CRITICAL 10.0
CVE-2026-23800
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 be…
Mitigation only
CRITICAL 9.8
CVE-2026-23744EPSS 45%
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vu…
Inspector
1.4.3+
CRITICAL 9.3
CVE-2012-10064
Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-co…
No fix yet
CRITICAL 9.8
CVE-2025-14894
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME val…
Filemanager
1.0.0+
CRITICAL 9.8
CVE-2025-59870
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci…
Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2025-60021EPSS 25%
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …
Brpc
1.15.0+
CRITICAL 9.8
CVE-2026-0975
Delta Electronics DIAView has Command Injection vulnerability.
Diaview
4.4.0+
CRITICAL 9.8
CVE-2026-1021
Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a…
Police Statistics Database System
after 1.0.2
CRITICAL 9.8
CVE-2026-1019
Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m…
Police Statistics Database System
after 1.0.3
CRITICAL 9.8
CVE-2025-62582
Delta Electronics DIAView has multiple vulnerabilities.
Diaview
4.4.0+
CRITICAL 9.8
CVE-2025-62581
Delta Electronics DIAView has multiple vulnerabilities.
Diaview
4.4.0+
CRITICAL 10.0
CVE-2025-61937
The vulnerability, if exploited, could allow an unauthenticated
miscreant to achieve remote code execution under OS system privileges of
“taoimr” s…
Process Optimization
2025+
CRITICAL 9.8
CVE-2025-14237
Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network …
Mf455dw Firmware
after 06.02
CRITICAL 9.8
CVE-2025-14236
Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment…
Mf455dw Firmware
after 06.02