Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2026-59501
CWE-284: Improper Access Control
No fix yet
HIGH 8.6
CVE-2026-59505
CWE-284: Improper Access Control
No fix yet
MEDIUM 5.3
CVE-2026-13328
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is als…
No fix yet
HIGH 7.8
CVE-2026-13367
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
Informix Dynamic Server
No fix yet
HIGH 7.8
CVE-2026-59914
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low pri…
Display And Peripheral Manager
No fix yet
HIGH 7.8
CVE-2026-59917
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attac…
Display And Peripheral Manager
No fix yet
MEDIUM 6.3
CVE-2026-67287
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on …
No fix yet
MEDIUM 5.3
CVE-2026-67284
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario…
No fix yet
MEDIUM 6.9
CVE-2026-67283
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var…
No fix yet
CRITICAL 9.1
CVE-2026-16538
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wall…
No fix yet
HIGH 8.2
CVE-2026-13171
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticate…
No fix yet
MEDIUM 5.8
CVE-2026-73212
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…
No fix yet
HIGH 7.8
CVE-2026-66804
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Windows 10 22h2
10.0.19045.7663 / 10.0.26100.9106+
HIGH 7.8
CVE-2026-65773
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
MEDIUM 6.5
CVE-2026-65675
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
Github Copilot Chat
No fix yet
HIGH 8.5
CVE-2026-20898
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of pri…
No fix yet
HIGH 8.4
CVE-2026-20789
Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg…
No fix yet
HIGH 8.3
CVE-2026-20741
Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unprivileged sof…
No fix yet
HIGH 7.2
CVE-2026-20716
Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary…
No fix yet
HIGH 7.5
CVE-2026-72600
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing…
No fix yet
HIGH 7.5
CVE-2026-72601
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally iden…
No fix yet
HIGH 8.8
CVE-2026-72561
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfi…
No fix yet
HIGH 8.1
CVE-2026-72563
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to oth…
No fix yet
HIGH 8.1
CVE-2026-72595
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to othe…
No fix yet
HIGH 8.1
CVE-2026-72596
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The …
No fix yet
MEDIUM 6.5
CVE-2026-72554
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations …
No fix yet
HIGH 8.1
CVE-2026-72555
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to fal…
No fix yet
HIGH 7.8
CVE-2026-72693
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k…
No fix yet
HIGH 7.1
CVE-2026-72909
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions pa…
No fix yet
HIGH 8.8
CVE-2026-18951
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme…
No fix yet