Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.1
CVE-2026-9725
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl…
Mitigation only
CRITICAL 10.0
CVE-2026-13768
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic…
Mitigation only
CRITICAL 9.3
CVE-2026-41106
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-26145
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
CRITICAL 9.4
CVE-2026-52830
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se…
No fix yet
CRITICAL 9.1
CVE-2026-38971
ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle…
Arduplane
after 4.6.3
CRITICAL 9.8
CVE-2026-38968
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cp…
Ntopng
after 6.6
CRITICAL 9.1
CVE-2026-59099
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversati…
Patch available
CRITICAL 9.8
CVE-2026-59092
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to acces…
Juicefs
after 1.3.1
CRITICAL 9.8
CVE-2026-58466
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the adminis…
Patch available
CRITICAL 9.9
CVE-2026-44935
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …
Rancher Fleet
0.12.15 / 0.13.11+
CRITICAL 9.8
CVE-2024-14037
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …
Mitigation only
CRITICAL 9.8
CVE-2022-50973
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…
Mitigation only
CRITICAL 9.8
CVE-2026-58455EPSS 8%
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comm…
Patch available
CRITICAL 10.0
CVE-2026-56004
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _…
Patch available
CRITICAL 9.8
CVE-2026-55116
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…
Unifi Connect
3.4.20+
CRITICAL 9.9
CVE-2026-55115
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…
Unifi Protect
7.1.83+
CRITICAL 9.8
CVE-2026-54408
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…
Unifi Protect
7.1.83+
CRITICAL 9.1
CVE-2026-54400
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica…
Unifi Access
4.2.29+
CRITICAL 9.9
CVE-2026-50748
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Applic…
Unifi Access
4.2.29+
CRITICAL 9.9
CVE-2026-50747
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi …
Unifi Talk Application
5.2.2+
CRITICAL 10.0
CVE-2026-50746
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C…
Unifi Connect Application
3.24.20+
CRITICAL 9.8
CVE-2026-4767
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse.
This issue affects WAF-A…
Mitigation only
CRITICAL 9.8
CVE-2026-5524
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…
Mitigation only
CRITICAL 9.3
CVE-2026-57683
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-57679
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-57677
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Mitigation only
CRITICAL 9.6
CVE-2026-57625
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Mitigation only
CRITICAL 10.0
CVE-2026-57624
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Mitigation only
CRITICAL 9.0
CVE-2026-57623
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
Mitigation only