Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-76242
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval …
No fix yet
CRITICAL 9.3
CVE-2026-74804
Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is inter…
No fix yet
CRITICAL 10.0
CVE-2026-74803
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-s…
No fix yet
CRITICAL 9.8
CVE-2026-16019
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows…
No fix yet
CRITICAL 9.3
CVE-2026-73391
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73390
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73389
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
No fix yet
CRITICAL 9.3
CVE-2026-73388
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73364
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73347
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
No fix yet
CRITICAL 9.3
CVE-2026-73185
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
No fix yet
CRITICAL 9.3
CVE-2026-73183
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
No fix yet
CRITICAL 10.0
CVE-2026-67364
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI…
No fix yet
CRITICAL 9.8
CVE-2026-66613
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
No fix yet
CRITICAL 9.3
CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…
No fix yet
CRITICAL 9.0
CVE-2026-18937
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalink…
No fix yet
CRITICAL 9.8
CVE-2026-18776
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…
No fix yet
CRITICAL 10.0
CVE-2026-18051
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthentic…
No fix yet
CRITICAL 9.8
CVE-2026-18031
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated wi…
No fix yet
CRITICAL 10.0
CVE-2026-76008
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…
No fix yet
CRITICAL 9.9
CVE-2026-76004
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th…
No fix yet
CRITICAL 9.9
CVE-2026-76003
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing…
No fix yet
CRITICAL 9.1
CVE-2026-11751
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow…
No fix yet
CRITICAL 9.9
CVE-2026-75976
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM.…
No fix yet
CRITICAL 9.3
CVE-2026-21580
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.…
No fix yet
CRITICAL 9.6
CVE-2026-76036
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbo…
Chrome
151.0.7922.169+
CRITICAL 9.6
CVE-2026-76035
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside …
No fix yet
CRITICAL 9.9
CVE-2026-73930
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.…
Helidon
No fix yet
CRITICAL 9.1
CVE-2026-73924
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.…
Helidon
No fix yet
CRITICAL 9.1
CVE-2026-73922
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.…
Helidon
No fix yet