Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-42463
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure …
Sqlbot
1.8.0+
HIGH 8.8
CVE-2026-33324
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vul…
Sqlbot
1.7.1+
HIGH 8.8
CVE-2026-32950
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab…
Sqlbot
1.7.0+
HIGH 7.5
CVE-2026-32949
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SS…
Sqlbot
1.7.0+
HIGH 8.8
CVE-2026-32622
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner…
Sqlbot
1.6.0+
MEDIUM 6.8
CVE-2026-31864
JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerabili…
Jumpserver
3.10.22 / 4.10.16+
MEDIUM 5.0
CVE-2026-31798
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly valida…
Jumpserver
4.10.16+
MEDIUM 5.9
CVE-2025-15598
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.…
Sqlbot
after 1.5.1
MEDIUM 6.3
CVE-2025-15597
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of t…
Sqlbot
1.5.0+
CRITICAL 9.8
CVE-2025-70981
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.
Cordys Crm
Mitigation only
MEDIUM 6.1
CVE-2025-69285
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerab…
Sqlbot
1.5.0+
HIGH 8.4
CVE-2026-23525
1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel…
1panel
1.10.34 / 2.0.17+
HIGH 7.1
CVE-2025-34429
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-chan…
1panel
after 2.0.15
HIGH 7.1
CVE-2025-34410
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the se…
1panel
after 2.0.15
HIGH 7.5
CVE-2025-66507
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable…
1panel
2.0.14+
MEDIUM 6.5
CVE-2025-66508
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts…
1panel
2.0.14+
MEDIUM 6.5
CVE-2025-14117
A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The …
Halo
No fix yet
MEDIUM 6.1
CVE-2025-58044
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// end…
Jumpserver
3.10.19 / 4.10.5+
HIGH 7.1
CVE-2025-62795
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privi…
Jumpserver
3.10.21 / 4.10.12+
HIGH 8.1
CVE-2025-62712
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4…
Jumpserver
3.10.20 / 4.10.11+
HIGH 8.8
CVE-2025-56413
OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation paramete…
1panel
Mitigation only
CRITICAL 9.8
CVE-2025-54424
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below…
1panel
2.0.6+
CRITICAL 9.8
CVE-2024-40629
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …
Jumpserver
3.10.12+
CRITICAL 9.1
CVE-2024-40628
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …
Jumpserver
3.10.12+
CRITICAL 9.8
CVE-2024-39907EPSS 29%
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, le…
1panel
1.10.12-lts+
CRITICAL 9.8
CVE-2024-39911
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has bee…
1panel
1.10.12-lts+
HIGH 7.5
CVE-2024-34352
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the pro…
1panel
1.10.3-lts+
MEDIUM 5.9
CVE-2024-30257
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol ins…
1panel
1.10.3-lts+
CRITICAL 9.9
CVE-2024-29202EPSS 6%
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection v…
Jumpserver
3.10.7+
CRITICAL 9.9
CVE-2024-29201EPSS 6%
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism…
Jumpserver
3.10.7+