Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-71256
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_…
No fix yet
CRITICAL 9.8
CVE-2026-71254
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in …
No fix yet
CRITICAL 9.8
CVE-2026-71248
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f…
Patch available
CRITICAL 9.1
CVE-2026-71238
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…
No fix yet
CRITICAL 9.8
CVE-2026-71237
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i…
No fix yet
CRITICAL 9.8
CVE-2026-71231
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b…
No fix yet
CRITICAL 9.8
CVE-2026-66747
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o…
No fix yet
CRITICAL 9.1
CVE-2026-44945
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w…
Patch available
CRITICAL 9.0
CVE-2026-10090
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet…
No fix yet
CRITICAL 9.1
CVE-2026-10059
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp…
No fix yet
CRITICAL 9.8
CVE-2026-71214
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS…
No fix yet
CRITICAL 9.1
CVE-2026-71213
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when capt…
No fix yet
CRITICAL 9.8
CVE-2026-71207
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly…
No fix yet
CRITICAL 9.6
CVE-2026-70376
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.ph…
No fix yet
CRITICAL 9.8
CVE-2026-64566
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
When iptfs_sk…
No fix yet
CRITICAL 9.8
CVE-2026-61486
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this pro…
Lucy
No fix yet
CRITICAL 9.8
CVE-2026-61484
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As th…
Lucy
Mitigation only
CRITICAL 9.1
CVE-2026-5581
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including…
No fix yet
CRITICAL 9.1
CVE-2026-4431
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos…
No fix yet
CRITICAL 10.0
CVE-2026-16940
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete…
No fix yet
CRITICAL 9.1
CVE-2026-15360
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthen…
Mitigation only
CRITICAL 9.1
CVE-2026-15210
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate…
No fix yet
CRITICAL 9.3
CVE-2026-9273
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading t…
Mitigation only
CRITICAL 9.1
CVE-2026-45537
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concate…
Patch available
CRITICAL 9.1
CVE-2026-45100
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in …
Patch available
CRITICAL 9.8
CVE-2026-70554
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control…
No fix yet
CRITICAL 9.1
CVE-2026-67979
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary …
Mitigation only
CRITICAL 9.8
CVE-2026-66902
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.
The Pluggable sub…
Patch available
CRITICAL 9.8
CVE-2026-45538
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longe…
No fix yet
CRITICAL 9.8
CVE-2026-70553
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co…
No fix yet