Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.9
CVE-2026-34048
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots…
Patch available
CRITICAL 9.9
CVE-2026-34047
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket boots…
Patch available
CRITICAL 9.9
CVE-2026-34037
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire a…
Patch available
CRITICAL 10.0
CVE-2026-57572
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra…
Crawl4ai
0.9.0+
CRITICAL 9.6
CVE-2026-57571
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w…
Crawl4ai
0.9.0+
CRITICAL 10.0
CVE-2026-54763
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewa…
Traefik
2.11.51 / 3.6.22+
CRITICAL 9.2
CVE-2026-42341
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab…
Mitigation only
CRITICAL 9.9
CVE-2026-34038
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote …
Patch available
CRITICAL 9.8
CVE-2026-11405
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.
- The function contains …
Mitigation only
CRITICAL 9.8
CVE-2026-9182
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi…
Arcgis Server
after 12.0
CRITICAL 9.9
CVE-2026-48614
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in …
Mitigation only
CRITICAL 10.0
CVE-2026-48316
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…
Coldfusion
Mitigation only
CRITICAL 9.9
CVE-2026-40141
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process…
Privileged Remote Access
25.3.3+
CRITICAL 9.8
CVE-2026-40139
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…
Privileged Remote Access
25.3.3+
CRITICAL 9.1
CVE-2026-5268
An authentication bypass vulnerability exists in
the default SFTP server component utilized across the Ciena products listed. This vulnerability allo…
Mitigation only
CRITICAL 9.1
CVE-2025-53830
Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for …
Mitigation only
CRITICAL 9.1
CVE-2025-53827
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15…
Mitigation only
CRITICAL 9.3
CVE-2026-12686
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted …
Mitigation only
CRITICAL 9.8
CVE-2026-56140
Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-s…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-53913
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.1
CVE-2026-48205
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operatio…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-48204
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs produce…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-46456
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map inbound message attributes into the Ca…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-46455
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel-keycloak security helper KeycloakSecurityHelper.parseAnd…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-46454
Improper Input Validation vulnerability in Apache Camel Cometd Component.
The camel-cometd component maps inbound Bayeux (CometD) message headers in…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-43867
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.1
CVE-2026-40047
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.
The camel-doclin…
Camel
4.18.3+
CRITICAL 9.8
CVE-2026-24014
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…
Iotdb
2.0.8+
CRITICAL 9.1
CVE-2026-24013
Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query handlers lack strict validation of the sessionId
parameter.…
Iotdb
2.0.8+