Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-62878
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9121+
CRITICAL 9.8
CVE-2026-62815
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.20348.5440 / 10.0.22631.7517+
CRITICAL 9.8
CVE-2026-59124
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Windows App
2.0.1314.0+
CRITICAL 9.6
CVE-2026-57104
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele…
Azure Storage Explorer
1.45.0+
CRITICAL 9.4
CVE-2026-50516
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
CRITICAL 10.0
CVE-2026-48362
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…
Coldfusion
No fix yet
CRITICAL 9.8
CVE-2026-12571
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
No fix yet
CRITICAL 9.3
CVE-2026-73080
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp…
Patch available
CRITICAL 9.1
CVE-2026-73069
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD…
Patch available
CRITICAL 9.3
CVE-2025-31114
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use…
Patch available
CRITICAL 9.8
CVE-2026-72920
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory auth…
Patch available
CRITICAL 9.1
CVE-2026-47702
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the …
Patch available
CRITICAL 10.0
CVE-2026-17061
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthen…
No fix yet
CRITICAL 9.8
CVE-2026-51584
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route…
No fix yet
CRITICAL 10.0
CVE-2026-48056
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat…
No fix yet
CRITICAL 9.3
CVE-2026-48046
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater…
No fix yet
CRITICAL 9.8
CVE-2026-46670
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat…
No fix yet
CRITICAL 9.1
CVE-2026-72748
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri…
Patch available
CRITICAL 10.0
CVE-2026-58115
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED ins…
No fix yet
CRITICAL 9.6
CVE-2026-18972
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead…
No fix yet
CRITICAL 9.9
CVE-2026-72603
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by inje…
No fix yet
CRITICAL 9.8
CVE-2026-72599
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. Th…
No fix yet
CRITICAL 9.8
CVE-2026-72550
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement…
No fix yet
CRITICAL 9.2
CVE-2026-13738
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res…
No fix yet
CRITICAL 9.2
CVE-2026-13737
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance …
No fix yet
CRITICAL 10.0
CVE-2026-58231
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain function…
No fix yet
CRITICAL 9.8
CVE-2026-10579
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…
No fix yet
CRITICAL 9.1
CVE-2026-19516
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…
No fix yet
CRITICAL 9.1
CVE-2026-13716
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path…
Crafty Controller
4.10.8+
CRITICAL 9.8
CVE-2026-19425
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…
No fix yet