Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-66691
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66478
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66472
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66465
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66458
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66453
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66446
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66436
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66424
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
No fix yet
CRITICAL 9.3
CVE-2026-61969
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-61967
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
No fix yet
CRITICAL 9.3
CVE-2026-61966
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
No fix yet
CRITICAL 10.0
CVE-2026-61962
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28185
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28149
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28148
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
No fix yet
CRITICAL 9.3
CVE-2026-28142
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28008
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
No fix yet
CRITICAL 9.3
CVE-2026-28001
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
No fix yet
CRITICAL 10.0
CVE-2026-27544
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-49827
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…
Patch available
CRITICAL 9.0
CVE-2026-73602
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code …
Patch available
CRITICAL 9.0
CVE-2026-73601
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing…
No fix yet
CRITICAL 9.0
CVE-2026-73487
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…
No fix yet
CRITICAL 9.0
CVE-2026-73486
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…
No fix yet
CRITICAL 9.0
CVE-2026-73485
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…
No fix yet
CRITICAL 9.4
CVE-2026-73483
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…
No fix yet
CRITICAL 9.3
CVE-2026-59507
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
No fix yet
CRITICAL 9.3
CVE-2026-59506
CWE-306: Missing Authentication for Critical Function
No fix yet
CRITICAL 9.1
CVE-2026-59504
CWE-602: Client-Side Enforcement of Server-Side Security
No fix yet