Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-53959
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account informatio…
Fix unknown
CRITICAL 9.0
CVE-2026-62988
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps…
Fix unknown
HIGH 7.5
CVE-2026-75915
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process e…
Fix unknown
HIGH 7.6
CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…
Fix unknown
CRITICAL 9.8
CVE-2026-42164
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…
Fix unknown
CRITICAL 9.6
CVE-2026-71424
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…
Fix unknown
MEDIUM 6.5
CVE-2026-64778
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, mac…
Safari
Fix unknown
MEDIUM 5.5
CVE-2026-64760
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak se…
Ipados
Fix unknown
HIGH 8.5
CVE-2026-57485
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en…
Fix unknown
MEDIUM 5.3
CVE-2026-68520
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and e…
Fix unknown
CRITICAL 9.1
CVE-2026-64859
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and…
Fix unknown
MEDIUM 6.2
CVE-2026-49302
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confide…
Fix unknown
MEDIUM 6.2
CVE-2026-49307
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentia…
Fix unknown
MEDIUM 6.2
CVE-2026-49301
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Fix unknown
MEDIUM 6.5
CVE-2026-19613
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom f…
Fix unknown
HIGH 7.5
CVE-2026-19717
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, all…
Fix unknown
MEDIUM 6.2
CVE-2026-73047
siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature …
No fix yet
MEDIUM 6.5
CVE-2026-16541
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those…
Fix unknown
HIGH 7.5
CVE-2026-16611
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read rout…
Fix unknown
MEDIUM 5.3
CVE-2026-66272
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate…
Wyse Management Suite
No fix yet
HIGH 7.7
CVE-2026-72670
A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would…
No fix yet
MEDIUM 6.5
CVE-2026-58442
Repository migration SSRF via multi-answer DNS allow-list bypass
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
HIGH 7.5
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
No fix yet
MEDIUM 6.5
CVE-2026-57897
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
No fix yet
HIGH 7.5
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
No fix yet
CRITICAL 9.1
CVE-2026-55982
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
No fix yet
HIGH 7.5
CVE-2026-73622
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to ex…
No fix yet
MEDIUM 6.5
CVE-2026-73604
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted sec…
No fix yet
CRITICAL 9.1
CVE-2026-59503
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
No fix yet