Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-67822
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sp…
No fix yet
CRITICAL 9.4
CVE-2026-58048
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
No fix yet
CRITICAL 9.9
CVE-2026-52855
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg…
Patch available
CRITICAL 9.9
CVE-2026-17566
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi…
Pgadmin 4
9.18+
CRITICAL 9.0
CVE-2026-17351
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar…
Pgadmin 4
9.17+
CRITICAL 9.6
CVE-2026-17349
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…
Pgadmin 4
9.17+
CRITICAL 9.8
CVE-2026-16504
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HT…
Mitigation only
CRITICAL 9.1
CVE-2026-16503
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default…
No fix yet
CRITICAL 9.8
CVE-2026-17561
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign…
No fix yet
CRITICAL 9.3
CVE-2025-67649
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into paramet…
No fix yet
CRITICAL 10.0
CVE-2026-18452
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP…
No fix yet
CRITICAL 9.8
CVE-2026-14919
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t…
No fix yet
CRITICAL 9.8
CVE-2026-14483
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5…
Mitigation only
CRITICAL 9.8
CVE-2026-63223
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe c…
Patch available
CRITICAL 9.4
CVE-2026-63221
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions…
Patch available
CRITICAL 9.8
CVE-2026-43830
Full details and mitigation steps are currently restricted and will be published at a later date.
No fix yet
CRITICAL 9.8
CVE-2026-14537
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated at…
Mcp Toolbox For Databases
Patch available
CRITICAL 9.3
CVE-2026-66421
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript …
No fix yet
CRITICAL 9.8
CVE-2026-38709
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer…
No fix yet
CRITICAL 9.8
CVE-2026-68503
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn a…
Patch available
CRITICAL 9.8
CVE-2026-68502
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticat…
Patch available
CRITICAL 10.0
CVE-2026-66803
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Azure Cosmos Db
No fix yet
CRITICAL 9.3
CVE-2026-66418
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML …
No fix yet
CRITICAL 9.1
CVE-2026-52539
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back…
No fix yet
CRITICAL 9.8
CVE-2026-35847
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
Mitigation only
CRITICAL 9.8
CVE-2025-69931
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
No fix yet
CRITICAL 9.8
CVE-2025-69947
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
No fix yet
CRITICAL 9.8
CVE-2025-69941
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
No fix yet
CRITICAL 9.8
CVE-2025-69938
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
No fix yet
CRITICAL 9.8
CVE-2025-69937
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
Mitigation only