Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-35671
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated ad…
Mitigation only
HIGH 7.3
CVE-2026-9795
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo…
Build Of Keycloak
Mitigation only
CRITICAL 9.8
CVE-2026-42758
Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affe…
Mitigation only
CRITICAL 9.8
CVE-2026-42731
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This i…
Mitigation only
HIGH 7.3
CVE-2026-9580
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDep…
Mitigation only
MEDIUM 6.3
CVE-2026-9581
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation …
Mitigation only
MEDIUM 6.3
CVE-2026-9579
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the com…
Mitigation only
HIGH 7.3
CVE-2026-9562
A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unkn…
Mitigation only
HIGH 7.3
CVE-2026-9517
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/…
Mitigation only
HIGH 8.8
CVE-2026-45216
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
This issue affects Smart Manager: from n/a thro…
Mitigation only
MEDIUM 6.3
CVE-2026-9484
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStu…
Mitigation only
MEDIUM 6.3
CVE-2026-9483
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing …
Mitigation only
MEDIUM 6.3
CVE-2026-9412
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Exec…
No fix yet
HIGH 8.1
CVE-2026-9397
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the componen…
Mitigation only
MEDIUM 6.3
CVE-2026-9376
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the com…
Mitigation only
HIGH 7.8
CVE-2025-32747
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access c…
Powerflex Appliance Intelligent Catalog
3.7.8.0 / 48.383.00+
CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…
Litespeed Cpanel Plugin
2.4.7 / 5.3.1.0+
HIGH 7.2
CVE-2026-22315
Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user d…
Mitigation only
MEDIUM 5.3
CVE-2026-8752
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapid…
H2o
after 7402
MEDIUM 6.3
CVE-2026-8747
A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of t…
Mitigation only
MEDIUM 6.3
CVE-2026-8743
A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the compon…
Open5gs
after 2.7.6
HIGH 7.5
CVE-2025-68420
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is …
Mitigation only
MEDIUM 6.5
CVE-2026-35062
An authenticated iControl SOAP user may be able to obtain information of other accounts.
Note: Software versions which have reached End of Technica…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 5.3
CVE-2026-8241
A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of …
Mitigation only
HIGH 7.8
CVE-2026-8148
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation du…
Mybox
3.0.11.160+
MEDIUM 6.3
CVE-2026-8127
A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users…
Mitigation only
MEDIUM 5.9
CVE-2026-43510
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges …
Patch available
HIGH 8.1
CVE-2026-43535
OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different sen…
Openclaw
2026.4.14+
CRITICAL 9.9
CVE-2026-42368
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request ca…
Gv Lpc2011 Firmware
Mitigation only
MEDIUM 6.3
CVE-2026-7713
A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token …
Patch available