Top technology
Linux 13139
Google 12756
Microsoft 12402
Oracle 7445
Apple 6698
Ibm 6475
Adobe 6427
Cisco 5767
Debian 3920
Apache 2924
Mozilla 2912
Redhat 2626
CRITICAL 9.3
CVE-2025-41006
Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
Mitigation only
CRITICAL 9.8
CVE-2025-69270
Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.Thi…
Dx Netops Spectrum
24.3.9+
CRITICAL 9.8
CVE-2025-69269
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L…
Dx Netops Spectrum
23.3.7+
CRITICAL 9.8
CVE-2025-52694EPSS 39%
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu…
Iot Edge Linux Docker
2.0.2 / 3.4.15+
CRITICAL 9.8
CVE-2026-0852
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH…
Online Music Site
Mitigation only
CRITICAL 9.8
CVE-2026-0851
A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/Adm…
Online Music Site
Mitigation only
CRITICAL 9.8
CVE-2026-0821
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file qui…
Quickjs
after 0.11.0
CRITICAL 9.8
CVE-2025-15503
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15502EPSS 6%
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2026-22685
DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension i…
Devtoys
2.0.9.0+
CRITICAL 9.8
CVE-2026-22687
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th…
Weknora
0.2.5+
CRITICAL 10.0
CVE-2025-65091
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServi…
Full Calendar Macro
2.4.5+
CRITICAL 9.1
CVE-2025-61686EPSS 17%
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node …
React Router\/node
2.17.2 / 7.9.4+
CRITICAL 9.1
CVE-2026-22600
OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…
Openproject
16.6.4+
CRITICAL 9.8
CVE-2025-15501EPSS 7%
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2026-22584
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code…
Uni2ts
2.0.0+
CRITICAL 9.8
CVE-2025-15500EPSS 6%
A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …
Operation And Maintenance Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15499EPSS 5%
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…
Operation And Maintenance Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-70161EPSS 25%
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the …
Br 6208ac Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-69542EPSS 9%
A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r…
Dir 895la1 Firmware
Mitigation only
CRITICAL 10.0
CVE-2025-69426
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an …
Mitigation only
CRITICAL 10.0
CVE-2025-69425
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile…
Mitigation only
CRITICAL 9.8
CVE-2025-15496
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of th…
Yshopmall
after 1.9.1
CRITICAL 9.8
CVE-2025-15493
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMa…
Docsys
after 2.02.36
CRITICAL 9.3
CVE-2020-36875
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl…
Mitigation only
CRITICAL 9.8
CVE-2025-14598
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables ar…
Bet E Portal
Mitigation only
CRITICAL 9.3
CVE-2025-7072
The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an una…
Mitigation only
CRITICAL 9.8
CVE-2025-66050
Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is…
Ip7137 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-64093
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.
Icx500 Firmware
1.4.3.3+
CRITICAL 9.6
CVE-2025-13761
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unau…
GitLab
18.6.3+