Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2025-69689
The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied pa…
Mitigation only
HIGH 8.8
CVE-2026-7106
The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is d…
Mitigation only
HIGH 8.8
CVE-2026-41359
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class…
Openclaw
2026.3.28+
MEDIUM 5.9
CVE-2026-3621
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde…
Websphere Application Server
26.0.0.5+
MEDIUM 6.2
CVE-2026-6386
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which…
FreeBSD
Mitigation only
HIGH 8.8
CVE-2026-6761
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1…
Firefox
140.10.0 / 150.0+
HIGH 8.8
CVE-2026-6769
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140…
Firefox
140.10.0 / 150.0+
HIGH 8.8
CVE-2026-6750
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund…
Firefox
115.35.0 / 140.10.0+
HIGH 7.8
CVE-2026-31368
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
No fix yet
HIGH 8.8
CVE-2026-39386
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…
Neko
3.0.11 / 3.1.2+
MEDIUM 6.5
CVE-2026-29647
In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even …
Patch available
HIGH 8.8
CVE-2026-29648
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, l…
Patch available
MEDIUM 6.7
CVE-2026-35154
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…
Data Domain Operating System
7.13.1.70 / 8.3.1.30+
CRITICAL 9.9
CVE-2026-30269
Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role vi…
Doorman
Mitigation only
CRITICAL 9.3
CVE-2026-40317
NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary …
Novumos
0.24+
CRITICAL 9.0
CVE-2026-40572
NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 use…
Novumos
0.24+
CRITICAL 9.1
CVE-2026-40484
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive…
Patch available
MEDIUM 5.5
CVE-2025-70795
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate proce…
Patch available
HIGH 8.8
CVE-2026-40002
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems f…
Nubia In Nx809j Firmware
Mitigation only
HIGH 7.3
CVE-2026-23772
Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privile…
Mitigation only
CRITICAL 9.8
CVE-2026-4880
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege …
Mitigation only
HIGH 8.8
CVE-2026-34393
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This is…
Weblate
5.17+
HIGH 8.8
CVE-2026-40291
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th…
Chamilo Lms
after 1.11.38
MEDIUM 5.5
CVE-2026-32212
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32181
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
Windows 10 21h2
10.0.19044.7184 / 10.0.19045.7184+
HIGH 8.8
CVE-2026-38529
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to…
Krayin Crm
No fix yet
HIGH 8.8
CVE-2026-5144
The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the g…
Patch available
HIGH 7.1
CVE-2026-33706
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the u…
Chamilo Lms
1.11.38+
HIGH 8.3
CVE-2026-35595
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only…
Vikunja
2.3.0+
HIGH 7.8
CVE-2026-29923
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabli…
Mitigation only