Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-13717
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard…
No fix yet
MEDIUM 6.5
CVE-2026-72585
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the…
No fix yet
CRITICAL 9.1
CVE-2026-72575
An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergr…
No fix yet
MEDIUM 6.9
CVE-2026-21084
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
No fix yet
MEDIUM 5.5
CVE-2026-21064
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Android
No fix yet
HIGH 8.8
CVE-2026-17540
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a s…
No fix yet
MEDIUM 5.3
CVE-2026-17012
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a…
No fix yet
MEDIUM 6.3
CVE-2026-19358
A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation ca…
No fix yet
MEDIUM 5.3
CVE-2026-19357
A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy…
No fix yet
MEDIUM 5.3
CVE-2026-19356
A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-md…
No fix yet
HIGH 8.1
CVE-2026-16948
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects …
No fix yet
MEDIUM 6.3
CVE-2026-19210
A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?ac…
No fix yet
HIGH 8.7
CVE-2026-66494
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store…
No fix yet
CRITICAL 9.2
CVE-2026-54213
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/inter…
No fix yet
HIGH 8.5
CVE-2026-54208
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an
unauthenticated attacker to create or write …
No fix yet
MEDIUM 5.3
CVE-2026-12261
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts pa…
No fix yet
HIGH 7.8
CVE-2026-19192
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\…
No fix yet
HIGH 7.8
CVE-2026-19193
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter …
No fix yet
HIGH 7.8
CVE-2026-19195
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the co…
No fix yet
HIGH 8.8
CVE-2026-65668
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Purview Ediscovery
No fix yet
CRITICAL 9.6
CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Azure Logic Apps
No fix yet
HIGH 8.8
CVE-2026-67687
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro…
No fix yet
MEDIUM 6.3
CVE-2026-19065
A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of t…
No fix yet
CRITICAL 9.0
CVE-2025-14561
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing suffici…
No fix yet
MEDIUM 5.2
CVE-2026-55979
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is l…
No fix yet
HIGH 8.4
CVE-2026-55978
An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter co…
No fix yet
MEDIUM 5.4
CVE-2026-13703
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any l…
No fix yet
HIGH 8.2
CVE-2026-14829
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its…
No fix yet
MEDIUM 6.3
CVE-2026-18993
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent…
No fix yet
MEDIUM 5.3
CVE-2026-18974
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the compon…
No fix yet