Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-56260
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param…
Crawl4ai
0.8.7+
CRITICAL 10.0
CVE-2026-61447
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without…
Mitigation only
CRITICAL 9.9
CVE-2026-61445
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation a…
Mitigation only
CRITICAL 9.8
CVE-2026-60090
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() …
Patch available
CRITICAL 9.1
CVE-2026-56372
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory…
Imagemagick
7.1.2-19+
CRITICAL 9.8
CVE-2026-57827
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unaut…
Rsfiles\!
1.17.12+
CRITICAL 9.1
CVE-2026-15089
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
No fix yet
CRITICAL 9.8
CVE-2026-20744
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
Mitigation only
CRITICAL 9.9
CVE-2026-14480
OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy web UI program‑upload workflow. The
application store…
Mitigation only
CRITICAL 9.8
CVE-2026-11913
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
No fix yet
CRITICAL 9.2
CVE-2026-55884
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on…
Patch available
CRITICAL 9.8
CVE-2026-12535
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This …
Formatter Field
2.0.0+
CRITICAL 9.8
CVE-2026-10768
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0…
Localgov Workflows
1.6.0+
CRITICAL 9.8
CVE-2026-9726
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obj…
Alternativecommerce
2.1.17+
CRITICAL 9.8
CVE-2026-57807
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli…
Mitigation only
CRITICAL 10.0
CVE-2026-57216
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c…
Rabbitmq Server
4.2.6+
CRITICAL 10.0
CVE-2026-57211
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm…
Rabbitmq Server
4.2.6+
CRITICAL 9.3
CVE-2026-55879
OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page…
Patch available
CRITICAL 9.8
CVE-2026-12761
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …
Mitigation only
CRITICAL 9.1
CVE-2026-57158
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incompl…
Freerdp
3.28.0+
CRITICAL 9.8
CVE-2026-57156
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in upd…
Freerdp
3.28.0+
CRITICAL 9.8
CVE-2026-61459
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) t…
Mcp Server Kubernetes
3.9.0+
CRITICAL 9.8
CVE-2026-5801
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt…
Mitigation only
CRITICAL 9.6
CVE-2026-59151
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de…
Patch available
CRITICAL 9.8
CVE-2026-2397
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows…
Mitigation only
CRITICAL 9.2
CVE-2026-58492
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a…
Patch available
CRITICAL 9.1
CVE-2026-51119
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components
Mitigation only
CRITICAL 9.9
CVE-2026-55500
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, …
Patch available
CRITICAL 9.3
CVE-2026-15143
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Sc…
Mitigation only
CRITICAL 9.1
CVE-2026-61444
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int…
Mitigation only