Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-57621
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Mitigation only
CRITICAL 9.1
CVE-2026-27436
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Mitigation only
CRITICAL 9.9
CVE-2026-27419
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
No fix yet
CRITICAL 9.4
CVE-2026-14439
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence …
Mitigation only
CRITICAL 9.6
CVE-2026-14425
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14424
Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14423
Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14420
Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a …
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14419
Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14417
Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14416
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14411
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14405
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14398
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14397
Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a c…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14392
Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14390
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14387
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…
Chrome
150.0.7871.46+
CRITICAL 9.6
CVE-2026-14382
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo…
Chrome
150.0.7871.46+
CRITICAL 9.8
CVE-2026-52186
SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc c…
Mitigation only
CRITICAL 9.8
CVE-2026-58457
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent…
Mitigation only
CRITICAL 9.8
CVE-2026-14363
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…
Cargo
3.9.1+
CRITICAL 9.6
CVE-2026-53492
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic…
Containerd
2.1.9 / 2.2.5+
CRITICAL 9.8
CVE-2026-51947
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)…
Mitigation only
CRITICAL 9.9
CVE-2026-50195
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process…
Containerd
2.1.9 / 2.2.5+
CRITICAL 10.0
CVE-2026-50160
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated P…
Hoppscotch
2026.5.0+
CRITICAL 9.8
CVE-2026-58521
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…
Cargo
3.9.1+
CRITICAL 9.8
CVE-2026-58453
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent atta…
Mitigation only
CRITICAL 9.8
CVE-2026-34117
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"…
Mitigation only
CRITICAL 9.8
CVE-2026-34116
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php job…
Mitigation only