Top technology
Linux 13159
Google 12756
Microsoft 12402
Oracle 7453
Apple 6698
Ibm 6481
Adobe 6427
Cisco 5768
Debian 3920
Apache 2925
Mozilla 2920
Redhat 2626
CRITICAL 9.8
CVE-2025-64093
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.
Icx500 Firmware
1.4.3.3+
CRITICAL 9.6
CVE-2025-13761
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unau…
GitLab
18.6.3+
CRITICAL 9.8
CVE-2025-69194
A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Meta…
Wget2
2.2.1+
CRITICAL 9.1
CVE-2025-14741
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a …
Mitigation only
CRITICAL 9.1
CVE-2026-20973
Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.
Android
Mitigation only
CRITICAL 10.0
CVE-2025-70974
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, t…
Mitigation only
CRITICAL 9.8
CVE-2025-14736
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is du…
Mitigation only
CRITICAL 9.8
CVE-2026-0732EPSS 10%
A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the ar…
Di 8200g Firmware
Mitigation only
CRITICAL 9.4
CVE-2025-68717
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /…
Ks Wr3600 Firmware
No fix yet
CRITICAL 9.1
CVE-2025-68715
An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /go…
Pwru01 Firmware
No fix yet
CRITICAL 9.4
CVE-2025-66916
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres…
Ruoyi Vue Plus
after 5.5.1
CRITICAL 9.8
CVE-2025-66913
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke…
Jimureport
after 2.1.3
CRITICAL 9.8
CVE-2025-67325
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …
Qloapps
after 1.7.0
CRITICAL 9.8
CVE-2026-22234
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict…
Ecase Portal
9.0.45.0+
CRITICAL 9.8
CVE-2025-61548
SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions…
Print Shop Pro Webdesk
Mitigation only
CRITICAL 9.1
CVE-2025-61546
There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed i…
Print Shop Pro Webdesk
No fix yet
CRITICAL 9.8
CVE-2025-61246
indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.
Online Shopping System
Mitigation only
CRITICAL 9.0
CVE-2025-59470
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order para…
Veeam Backup \& Replication
13.0.1.1071+
CRITICAL 9.0
CVE-2025-59469
This vulnerability allows a Backup or Tape Operator to write files as root.
Veeam Backup \& Replication
13.0.1.1071+
CRITICAL 9.1
CVE-2025-59468
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a
malicious password paramet…
Veeam Backup \& Replication
13.0.1.1071+
CRITICAL 9.1
CVE-2025-56425
An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.18…
Enaio
10.10.0.183 / 11.0.0.183+
CRITICAL 9.8
CVE-2025-55125
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file.
Veeam Backup \& Replication
13.0.1.1071+
CRITICAL 9.8
CVE-2026-22043
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…
Rustfs
Mitigation only
CRITICAL 9.8
CVE-2026-22034
Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployme…
Snuffleupagus
0.13.0+
CRITICAL 9.8
CVE-2026-21891
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application…
Zimaos
after 1.5.0
CRITICAL 9.8
CVE-2025-69258
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a ke…
Apex Central
Mitigation only
CRITICAL 9.8
CVE-2025-62877
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x int…
Mitigation only
CRITICAL 9.3
CVE-2025-67928
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allow…
Mitigation only
CRITICAL 9.9
CVE-2025-67924
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affe…
Mitigation only
CRITICAL 9.8
CVE-2025-67911
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslet…
Mitigation only