Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-51808
Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, i…
Patch available
CRITICAL 9.8
CVE-2026-51807
Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by m…
Patch available
CRITICAL 9.1
CVE-2026-48807
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replac…
Twig
3.27.0+
CRITICAL 9.1
CVE-2026-48806
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP t…
Twig
3.27.0+
CRITICAL 9.1
CVE-2026-48805
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state…
Twig
3.27.0+
CRITICAL 9.3
CVE-2026-48334
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current use…
Illustrator
29.8.9 / 30.6+
CRITICAL 9.8
CVE-2026-46634
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template…
Twig
3.26.0+
CRITICAL 9.8
CVE-2026-46633
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p…
Twig
3.26.0+
CRITICAL 9.1
CVE-2026-45363
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'H…
Patch available
CRITICAL 9.8
CVE-2026-38450
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of…
Mitigation only
CRITICAL 9.1
CVE-2026-52101
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote fun…
Mitigation only
CRITICAL 9.1
CVE-2026-53486
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…
Patch available
CRITICAL 9.0
CVE-2026-48327
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …
Coldfusion
Mitigation only
CRITICAL 9.3
CVE-2026-48325
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context o…
Coldfusion
Mitigation only
CRITICAL 9.1
CVE-2026-48324
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …
Coldfusion
Mitigation only
CRITICAL 9.9
CVE-2026-48322
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in…
Coldfusion
Mitigation only
CRITICAL 9.3
CVE-2026-48321
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnera…
Coldfusion
Mitigation only
CRITICAL 9.1
CVE-2026-48319EPSS 32%
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitr…
Coldfusion
Mitigation only
CRITICAL 9.9
CVE-2026-48318
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrar…
Coldfusion
Mitigation only
CRITICAL 9.6
CVE-2026-48284
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2026-24227
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability…
Tensorrt
11.0+
CRITICAL 9.6
CVE-2026-15773
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a cr…
Chrome
150.0.7871.125+
CRITICAL 9.8
CVE-2026-53633
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarde…
Patch available
CRITICAL 9.6
CVE-2026-48359
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…
Experience Manager
after 2020.5.0
CRITICAL 9.1
CVE-2026-48358
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context o…
Commerce
1.21.0+
CRITICAL 9.3
CVE-2026-48356
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the c…
Commerce
1.21.0+
CRITICAL 9.6
CVE-2026-48259
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…
Experience Manager
after 2020.5.0
CRITICAL 9.6
CVE-2026-47428
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCa…
Patch available
CRITICAL 10.0
CVE-2026-15409 KEVEPSS 84%
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…
Sma6210 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-13001
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle…
Patch available