Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.9
CVE-2026-66780
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…
Fix unknown
MEDIUM 5.1
CVE-2026-73372
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access che…
Fix unknown
MEDIUM 5.1
CVE-2026-72531
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check …
Fix unknown
HIGH 8.6
CVE-2026-54730
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow with…
Fix unknown
MEDIUM 5.1
CVE-2026-73371
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori…
Fix unknown
HIGH 8.5
CVE-2026-71574
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a…
Fix unknown
MEDIUM 5.1
CVE-2026-72532
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow…
Fix unknown
HIGH 8.1
CVE-2026-50138
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-…
Fix unknown
CRITICAL 9.8
CVE-2026-74979
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird …
Fix unknown
MEDIUM 6.3
CVE-2024-14046
A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro…
Fix unknown
CRITICAL 9.8
CVE-2026-42163
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…
Fix unknown
CRITICAL 9.8
CVE-2026-68004
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev…
Fix unknown
CRITICAL 9.8
CVE-2026-73061
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties…
No fix yet
MEDIUM 6.5
CVE-2026-19711
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allow…
Fix unknown
MEDIUM 6.3
CVE-2026-19918
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag…
No fix yet
MEDIUM 5.3
CVE-2026-14229
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of…
Fix unknown
MEDIUM 5.1
CVE-2026-71570
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_ic…
No fix yet
HIGH 8.8
CVE-2026-72837
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers wi…
No fix yet
HIGH 8.6
CVE-2026-73664
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…
No fix yet
MEDIUM 6.8
CVE-2026-58440
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet…
No fix yet
MEDIUM 5.3
CVE-2026-58507
Private Repository Existence Disclosure via go-get Meta Endpoint
No fix yet
CRITICAL 9.1
CVE-2026-58508
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
No fix yet
HIGH 7.1
CVE-2026-58437
Repository Visibility Manipulation via Git Push Options
No fix yet
HIGH 8.1
CVE-2026-58439
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
No fix yet
HIGH 7.5
CVE-2026-58417
REST API exposes organization membership of private organizations to public
No fix yet
CRITICAL 9.8
CVE-2026-56654
Privilege Escalation via Access Token Scope Escalation in API
No fix yet
MEDIUM 6.2
CVE-2026-56657
Gitea SSH Key Parser Denial of Service
No fix yet
CRITICAL 9.1
CVE-2026-56750
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
No fix yet
MEDIUM 6.2
CVE-2026-56755
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
No fix yet
MEDIUM 5.4
CVE-2026-55986
Email Management API Bypasses ManageCredentials Feature Restrictions
No fix yet