Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-1556
Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenti…
Filefield Paths
7.x-1.3+
MEDIUM 5.3
CVE-2025-55276
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.
Aftermarket Cloud
Mitigation only
MEDIUM 5.3
CVE-2025-55272
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which…
Aftermarket Cloud
Mitigation only
HIGH 7.5
CVE-2025-55265
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma…
Aftermarket Cloud
Mitigation only
HIGH 7.2
CVE-2025-14915
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A …
Websphere Application Server
26.0.0.4+
MEDIUM 5.5
CVE-2026-28877
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, m…
Ipados
15.7.5 / 26.4+
MEDIUM 6.5
CVE-2026-28878
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoi…
Ipados
14.8.5 / 18.7.7+
MEDIUM 5.3
CVE-2026-28820
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
macOS
26.4+
MEDIUM 6.5
CVE-2026-33353
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo…
Soft Serve
0.11.6+
MEDIUM 6.5
CVE-2026-33627
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, …
Parse Server
8.6.61 / 9.6.0+
MEDIUM 6.5
CVE-2026-33677
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns…
Vikunja
2.2.1+
HIGH 7.5
CVE-2026-4712
Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…
Firefox
140.9.0 / 149.0+
MEDIUM 5.3
CVE-2026-4733
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
Patch available
HIGH 7.5
CVE-2025-60949
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to config…
Csweb
Patch available
MEDIUM 5.3
CVE-2026-23486
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…
Blinko
1.8.4+
MEDIUM 5.5
CVE-2026-27131
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.…
Patch available
MEDIUM 5.3
CVE-2025-13997
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to…
Mitigation only
HIGH 7.5
CVE-2026-33180
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers…
Mitigation only
MEDIUM 5.3
CVE-2026-33041
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing al…
Avideo
26.0+
MEDIUM 6.5
CVE-2026-32938
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed …
Siyuan
3.6.1+
CRITICAL 9.6
CVE-2026-32890
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…
Anchorr
after 1.4.1
MEDIUM 6.5
CVE-2026-30891
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's priv…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.5
CVE-2026-29108
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated A…
Suitecrm
8.9.3+
MEDIUM 6.5
CVE-2026-33355
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not a…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.5
CVE-2026-32099
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled,…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.5
CVE-2026-32002
OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly …
Openclaw
2026.2.23+
HIGH 7.5
CVE-2026-23659
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…
Azure Data Factory
No fix yet
CRITICAL 9.8
CVE-2026-32865
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…
Ecase Ecomplaint
10.1.0.0+
MEDIUM 6.5
CVE-2026-33163
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `P…
Parse Server
8.6.50 / 9.6.0+
CRITICAL 9.1
CVE-2026-32633
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…
Glances
4.5.2+