Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.0
CVE-2026-57898
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauth…
Mitigation only
CRITICAL 9.2
CVE-2026-15183
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat…
Mitigation only
CRITICAL 9.6
CVE-2026-11563
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper au…
Mitigation only
CRITICAL 9.1
CVE-2026-44761
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in …
Mitigation only
CRITICAL 9.9
CVE-2026-44747
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption t…
Mitigation only
CRITICAL 9.1
CVE-2026-27690
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t…
Mitigation only
CRITICAL 9.1
CVE-2026-58102
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts.
When building t…
Crypt\
2.1.3+
CRITICAL 9.1
CVE-2026-62327
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP…
Mitigation only
CRITICAL 9.8
CVE-2026-52533
An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file
No fix yet
CRITICAL 9.8
CVE-2026-59801
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API…
Mitigation only
CRITICAL 9.8
CVE-2026-51821
SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUser…
Mitigation only
CRITICAL 9.1
CVE-2026-51541
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath si…
Opener
Mitigation only
CRITICAL 9.8
CVE-2026-51540
OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing …
Opener
Mitigation only
CRITICAL 9.1
CVE-2026-51538
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th…
Opener
Mitigation only
CRITICAL 9.1
CVE-2026-51537
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing sh…
Opener
Mitigation only
CRITICAL 9.1
CVE-2026-51536
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed…
Opener
Mitigation only
CRITICAL 9.1
CVE-2026-58409
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) …
Mitigation only
CRITICAL 9.5
CVE-2026-6875EPSS 78%
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an …
Mitigation only
CRITICAL 9.8
CVE-2026-61500
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of th…
Mitigation only
CRITICAL 9.8
CVE-2026-57433
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a sign…
Storable
3.41+
CRITICAL 9.1
CVE-2026-13221
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is co…
Perl
after 5.43.9
CRITICAL 9.3
CVE-2026-6847
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos…
Mitigation only
CRITICAL 9.8
CVE-2026-61498
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote una…
Flamingo
after 4.12.2
CRITICAL 9.8
CVE-2026-60121
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers…
Flamingo
after 4.12.2
CRITICAL 9.1
CVE-2026-40469
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap…
Gawk
after 5.4.0
CRITICAL 9.1
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating …
Gawk
after 5.4.0
CRITICAL 9.3
CVE-2026-12257
Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/…
Mitigation only
CRITICAL 9.4
CVE-2026-14934
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versio…
Mitigation only
CRITICAL 9.8
CVE-2026-59518
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a thr…
Mitigation only
CRITICAL 9.3
CVE-2026-59515
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows…
Mitigation only