Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.4
CVE-2026-18702
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe…
No fix yet
HIGH 8.8
CVE-2026-15426
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by…
No fix yet
HIGH 7.7
CVE-2026-73218
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do…
No fix yet
HIGH 7.8
CVE-2026-68821
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
App Installer
1.30.80+
HIGH 7.1
CVE-2026-20890
Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation o…
No fix yet
HIGH 8.8
CVE-2026-72534
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token…
No fix yet
HIGH 8.8
CVE-2026-72537
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token…
No fix yet
HIGH 8.8
CVE-2026-18950
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy…
No fix yet
CRITICAL 9.9
CVE-2026-72886
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…
No fix yet
CRITICAL 9.9
CVE-2026-72863
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…
No fix yet
MEDIUM 6.7
CVE-2026-16742
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
No fix yet
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-16298
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset th…
No fix yet
HIGH 7.2
CVE-2026-14237
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-s…
No fix yet
HIGH 7.8
CVE-2026-19381
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library N…
No fix yet
CRITICAL 9.8
CVE-2026-14526
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du…
No fix yet
CRITICAL 9.9
CVE-2026-64637
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th…
No fix yet
HIGH 8.8
CVE-2026-15215
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscription…
No fix yet
HIGH 7.8
CVE-2026-19189
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows…
No fix yet
CRITICAL 9.9
CVE-2026-48086
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr…
No fix yet
CRITICAL 9.8
CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitati…
Api Control Plane
4.0.0.384 / 4.1.0.248+
MEDIUM 6.3
CVE-2026-19005
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/cre…
No fix yet
MEDIUM 6.3
CVE-2026-19007
A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/a…
No fix yet
CRITICAL 9.9
CVE-2026-9193
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate…
No fix yet
HIGH 8.1
CVE-2026-7327
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 all…
No fix yet
CRITICAL 9.9
CVE-2026-7329
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.…
No fix yet
CRITICAL 9.9
CVE-2026-8709
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …
No fix yet
MEDIUM 5.4
CVE-2026-16071
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when…
Build Of Keycloak
26.4.14 / 26.6.5+
HIGH 8.8
CVE-2026-18322
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to …
No fix yet
HIGH 8.4
CVE-2026-64634
A vulnerability allowing local privilege escalation to the Reporter service context.
No fix yet