Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.6
CVE-2026-59499
CWE-200: Exposure of Sensitive
Information to an Unauthorized Actor
No fix yet
MEDIUM 6.3
CVE-2026-73411
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~…
No fix yet
HIGH 7.5
CVE-2026-73406
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/sr…
No fix yet
MEDIUM 5.7
CVE-2026-73308
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results co…
No fix yet
HIGH 8.6
CVE-2026-72804
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve …
No fix yet
MEDIUM 5.3
CVE-2026-18673
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to …
No fix yet
MEDIUM 6.5
CVE-2026-65017
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…
Airflow
3.3.1+
MEDIUM 5.3
CVE-2026-19073
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and…
No fix yet
MEDIUM 6.5
CVE-2026-18943
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low …
No fix yet
HIGH 7.5
CVE-2026-18049
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and b…
No fix yet
HIGH 7.5
CVE-2026-16253
The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes …
No fix yet
HIGH 7.5
CVE-2026-14925
The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthe…
No fix yet
MEDIUM 6.5
CVE-2026-13168
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level acces…
No fix yet
MEDIUM 6.5
CVE-2026-12976
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against tha…
No fix yet
HIGH 7.5
CVE-2026-73246
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp…
No fix yet
MEDIUM 5.9
CVE-2026-73230
Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte len…
No fix yet
HIGH 8.2
CVE-2026-48771
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien…
No fix yet
HIGH 7.6
CVE-2026-48767
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth ac…
No fix yet
MEDIUM 5.3
CVE-2026-73082
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t…
No fix yet
MEDIUM 6.5
CVE-2026-66301
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose informat…
Dynamics 365
No fix yet
HIGH 7.5
CVE-2026-65769
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a n…
Teams
8.8.1+
MEDIUM 6.5
CVE-2026-61921
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.5
CVE-2026-61924
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.5
CVE-2026-61918
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.6
CVE-2026-59130
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-54123
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…
Defender For Endpoint
No fix yet
MEDIUM 6.3
CVE-2026-20737
Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers …
No fix yet
HIGH 7.6
CVE-2026-48766
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible …
No fix yet
MEDIUM 6.2
CVE-2026-72744
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome D…
No fix yet
HIGH 7.5
CVE-2026-72548
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation …
No fix yet