Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.7
CVE-2026-34242
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following …
Weblate
5.17+
MEDIUM 5.0
CVE-2026-34244
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat…
Weblate
5.17+
HIGH 7.4
CVE-2026-32631
Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's…
Mitigation only
MEDIUM 6.5
CVE-2025-12141
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.not…
Grafana
after 12.3.0
MEDIUM 6.5
CVE-2026-25219
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p…
Airflow
3.2.0+
MEDIUM 6.5
CVE-2026-32151
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32085
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information loc…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32084
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32079
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32081
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 6.5
CVE-2026-34984
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and…
External Secrets Operator
2.3.0+
MEDIUM 5.3
CVE-2026-6160
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of th…
No fix yet
MEDIUM 5.3
CVE-2026-3691
OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affe…
Openclaw
2026.2.25+
MEDIUM 5.5
CVE-2026-40159
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers vi…
Praisonai
4.5.128+
MEDIUM 6.1
CVE-2026-31262
Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and e…
Sportsbook
No fix yet
MEDIUM 5.3
CVE-2026-40151
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent name…
Praisonai
4.5.128+
MEDIUM 6.5
CVE-2026-39943
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revi…
Directus
11.17.0+
HIGH 7.5
CVE-2026-4660
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously craf…
Mitigation only
HIGH 7.5
CVE-2025-62188
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.
This vulnerability may allow unauthor…
Dolphinscheduler
3.2.0+
HIGH 7.5
CVE-2026-39889
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity withou…
Praisonai
after 4.5.114
HIGH 7.5
CVE-2026-39412
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropert…
Liquidjs
10.25.4+
MEDIUM 5.3
CVE-2026-3594
The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '…
Mitigation only
HIGH 7.5
CVE-2026-39363
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve…
Vite
after 8.0.4
MEDIUM 5.3
CVE-2026-35449
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabl…
Avideo
after 26.0
MEDIUM 5.3
CVE-2026-35452
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log…
Avideo
after 26.0
MEDIUM 5.3
CVE-2026-35413
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Di…
Directus
11.16.1+
HIGH 8.1
CVE-2026-35442
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields w…
Directus
11.17.0+
MEDIUM 5.3
CVE-2026-5666
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql…
Mitigation only
HIGH 7.5
CVE-2026-34969
Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token …
Nhost\/auth
0.48.0+
MEDIUM 5.3
CVE-2026-5650
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/datab…
No fix yet