Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-59792
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
Intellij Idea
2026.1.4+
CRITICAL 9.8
CVE-2026-56765
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling p…
Mitigation only
CRITICAL 9.1
CVE-2026-56688
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject…
Powerflex Manager
4.5.5.2 / 5.1.0.1+
CRITICAL 9.8
CVE-2026-53363
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
iptfs_consume…
Linux Kernel
6.18.36 / 7.0.13+
CRITICAL 9.0
CVE-2026-41880
R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-…
Mitigation only
CRITICAL 9.3
CVE-2026-15378
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery …
Mitigation only
CRITICAL 9.8
CVE-2026-40008
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB.
The pipe processor reads a fully
qu…
Mitigation only
CRITICAL 9.1
CVE-2026-40005
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
An attacker can write arbitrary files a…
Mitigation only
CRITICAL 9.8
CVE-2026-28564
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.
REST Basic Authentication Accepts Stale Cache…
Mitigation only
CRITICAL 9.1
CVE-2026-15300
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, …
Mitigation only
CRITICAL 9.8
CVE-2026-15282
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_…
Mitigation only
CRITICAL 9.8
CVE-2026-14894
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 …
Patch available
CRITICAL 9.2
CVE-2026-55615
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher q…
Patch available
CRITICAL 10.0
CVE-2026-54769
Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape …
Mitigation only
CRITICAL 9.3
CVE-2026-54760
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,…
Mitigation only
CRITICAL 9.8
CVE-2026-58123
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell …
Patch available
CRITICAL 9.1
CVE-2026-58122
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin …
Patch available
CRITICAL 9.0
CVE-2026-53963
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-c…
Discourse
2026.1.5 / 2026.4.2+
CRITICAL 9.1
CVE-2026-54003
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly a…
Patch available
CRITICAL 9.9
CVE-2026-0284
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacke…
Pan Os
10.2.7 / 10.2.10+
CRITICAL 9.1
CVE-2026-59826
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di…
Metabase
1.58.15.1 / 1.59.12+
CRITICAL 10.0
CVE-2026-59726EPSS 7%
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp…
Patch available
CRITICAL 9.0
CVE-2026-59216
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex…
Open Webui
0.10.0+
CRITICAL 9.0
CVE-2026-59214
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodid…
Open Webui
0.10.0+
CRITICAL 9.6
CVE-2026-58459
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS…
Gpsd
after 3.27.5
CRITICAL 9.8
CVE-2026-51599
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remot…
No fix yet
CRITICAL 9.1
CVE-2026-51597
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network atta…
Mitigation only
CRITICAL 9.6
CVE-2026-13461
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specifi…
Mitigation only
CRITICAL 9.4
CVE-2026-42486
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure d…
No fix yet
CRITICAL 9.4
CVE-2026-23562
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure d…
Mitigation only