Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-9103
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a…
Langflow
1.10.1+
CRITICAL 9.8
CVE-2026-9202
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A…
Langflow
1.10.1+
CRITICAL 9.8
CVE-2026-9198 KEVEPSS 37%
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…
Langflow
1.10.1+
CRITICAL 9.3
CVE-2026-9586
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning…
No fix yet
CRITICAL 9.8
CVE-2026-8297
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laborato…
No fix yet
CRITICAL 9.3
CVE-2026-54496
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.…
No fix yet
CRITICAL 9.1
CVE-2026-12694
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This…
No fix yet
CRITICAL 9.4
CVE-2026-12693
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly…
No fix yet
CRITICAL 9.8
CVE-2026-12692
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.
This issue affects Enterprise Vide…
No fix yet
CRITICAL 9.8
CVE-2026-60024
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0…
No fix yet
CRITICAL 9.8
CVE-2026-51080
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Libpve Storage Perl
No fix yet
CRITICAL 9.1
CVE-2024-23564
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server …
No fix yet
CRITICAL 9.8
CVE-2026-9810
The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …
Mitigation only
CRITICAL 9.8
CVE-2026-15982
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al…
Mitigation only
CRITICAL 9.1
CVE-2026-62241EPSS 7%
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as t…
Clawvet
0.7.5+
CRITICAL 9.8
CVE-2026-14956
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val…
No fix yet
CRITICAL 10.0
CVE-2026-44182
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…
Enterprise Gateway
3.3.0+
CRITICAL 10.0
CVE-2026-44181
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…
Enterprise Gateway
3.3.0+
CRITICAL 9.1
CVE-2026-57075
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
The base64 decoder in t…
Patch available
CRITICAL 9.8
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…
Workplace Desktop
6.5.18 / 6.6.15+
CRITICAL 9.8
CVE-2026-44180
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers…
Enterprise Gateway
3.3.0+
CRITICAL 9.8
CVE-2026-38158
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform…
No fix yet
CRITICAL 9.3
CVE-2026-63089
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows un…
Patch available
CRITICAL 9.1
CVE-2026-15422
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chu…
Patch available
CRITICAL 9.9
CVE-2026-54526
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow…
Argo Workflows
3.7.15 / 4.0.6+
CRITICAL 9.3
CVE-2026-46515
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pin…
Patch available
CRITICAL 9.9
CVE-2026-46512
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, de…
Patch available
CRITICAL 10.0
CVE-2026-45336
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,…
No fix yet
CRITICAL 9.1
CVE-2026-57074
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter stri…
Patch available
CRITICAL 9.1
CVE-2026-57073
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter str…
Patch available