Top technology
Linux 13139
Google 12756
Microsoft 12402
Oracle 7445
Apple 6698
Ibm 6475
Adobe 6427
Cisco 5767
Debian 3920
Apache 2924
Mozilla 2912
Redhat 2626
CRITICAL 9.8
CVE-2025-68775
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: duplicate handshake cancellations leak socket
When a handshake r…
Mitigation only
CRITICAL 9.8
CVE-2025-65783
An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to …
Hub
Mitigation only
CRITICAL 9.0
CVE-2025-12548
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltratio…
Mitigation only
CRITICAL 9.3
CVE-2026-22755EPSS 21%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365…
Mitigation only
CRITICAL 9.8
CVE-2026-0892
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Firefox
147.0+
CRITICAL 9.8
CVE-2026-0884
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1…
Firefox
140.7.0 / 147.0+
CRITICAL 10.0
CVE-2026-0881
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Firefox
147.0+
CRITICAL 9.8
CVE-2026-0879
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef…
Firefox
115.32.0 / 140.7.0+
CRITICAL 9.1
CVE-2025-11250
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
Manageengine Adselfservice Plus
6.5+
CRITICAL 10.0
CVE-2025-40805
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to c…
Mitigation only
CRITICAL 9.1
CVE-2025-14829
The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This ma…
Mitigation only
CRITICAL 9.8
CVE-2025-10915
The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.
Mitigation only
CRITICAL 9.9
CVE-2026-0501
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute cra…
Mitigation only
CRITICAL 9.1
CVE-2026-0491
SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en…
Mitigation only
CRITICAL 9.8
CVE-2026-22214
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds…
Riot
2025.10+
CRITICAL 9.8
CVE-2026-22213
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability…
Riot
2025.10+
CRITICAL 9.4
CVE-2025-67146
Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) train…
Gym Management System
No fix yet
CRITICAL 9.8
CVE-2025-29329
Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary…
F\@st 3686 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-12420EPSS 47%
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform t…
Now Assist Ai Agents
3.15.2 / 4.0.4+
CRITICAL 9.8
CVE-2025-67147
Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1…
Mitigation only
CRITICAL 9.8
CVE-2025-66802
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into …
Covid 19 Contact Tracing System
Mitigation only
CRITICAL 9.1
CVE-2025-51567
A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary…
Online Exam System
No fix yet
CRITICAL 9.8
CVE-2026-22785
orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l…
Orval
7.18.0+
CRITICAL 9.8
CVE-2026-22781
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via …
Tinyweb
1.98+
CRITICAL 9.9
CVE-2026-22252
LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida…
Librechat
Patch available
CRITICAL 9.1
CVE-2025-68472EPSS 19%
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f…
Mindsdb
25.11.1+
CRITICAL 10.0
CVE-2025-63314
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user pas…
Cm3 Acora Cms
Mitigation only
CRITICAL 9.8
CVE-2025-46070
An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component
Botmanager
Mitigation only
CRITICAL 9.9
CVE-2025-46066
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
Director
No fix yet
CRITICAL 9.8
CVE-2025-65552
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not impl…
Zx G12 Firmware
Mitigation only