Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-18615
A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b…
No fix yet
CRITICAL 9.8
CVE-2026-18614
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component…
No fix yet
CRITICAL 9.8
CVE-2026-18613
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the c…
No fix yet
CRITICAL 9.8
CVE-2026-18612
A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the…
No fix yet
CRITICAL 9.8
CVE-2026-41452
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit…
No fix yet
CRITICAL 9.1
CVE-2026-39932
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that al…
No fix yet
CRITICAL 9.8
CVE-2026-18602
A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc o…
No fix yet
CRITICAL 9.1
CVE-2026-18248
@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications…
No fix yet
CRITICAL 9.1
CVE-2026-9487
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve…
\
0.71+
CRITICAL 9.1
CVE-2026-9390
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.
verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions …
\
0.71+
CRITICAL 10.0
CVE-2026-69085
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is …
No fix yet
CRITICAL 10.0
CVE-2026-69084
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr…
No fix yet
CRITICAL 10.0
CVE-2026-69083
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and…
No fix yet
CRITICAL 9.8
CVE-2026-64827
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.…
No fix yet
CRITICAL 9.8
CVE-2026-18601
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon…
No fix yet
CRITICAL 9.8
CVE-2026-18108
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte…
Net\
0.86+
CRITICAL 9.8
CVE-2026-2346
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affe…
No fix yet
CRITICAL 9.3
CVE-2026-18574
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una…
No fix yet
CRITICAL 10.0
CVE-2026-33591
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security restriction using a specially …
No fix yet
CRITICAL 9.8
CVE-2026-18589
A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of th…
No fix yet
CRITICAL 9.8
CVE-2026-18588
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the arg…
No fix yet
CRITICAL 9.1
CVE-2026-16534
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du…
No fix yet
CRITICAL 9.1
CVE-2026-16532
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u…
Mitigation only
CRITICAL 9.8
CVE-2026-16300
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass…
No fix yet
CRITICAL 9.8
CVE-2026-16250
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi…
No fix yet
CRITICAL 9.8
CVE-2026-16060
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re…
No fix yet
CRITICAL 9.4
CVE-2026-15930
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value …
No fix yet
CRITICAL 9.8
CVE-2026-12872
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio…
No fix yet
CRITICAL 9.1
CVE-2026-14557
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-ver…
Mitigation only
CRITICAL 9.1
CVE-2026-12965
The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a…
No fix yet