Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.3
CVE-2026-16331
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…
No fix yet
HIGH 7.3
CVE-2026-16327
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …
No fix yet
HIGH 7.6
CVE-2026-55544
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…
No fix yet
HIGH 7.1
CVE-2026-55550
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…
No fix yet
HIGH 8.2
CVE-2026-47255
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…
Patch available
HIGH 7.3
CVE-2026-16324
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…
No fix yet
CRITICAL 9.1
CVE-2026-62414
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac…
Mitigation only
HIGH 8.7
CVE-2026-60030
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …
No fix yet
HIGH 8.2
CVE-2026-46415
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to vers…
Patch available
MEDIUM 5.3
CVE-2026-12972
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava…
No fix yet
MEDIUM 5.3
CVE-2026-16201
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of…
No fix yet
MEDIUM 6.5
CVE-2026-51083
Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privilege…
No fix yet
CRITICAL 9.9
CVE-2026-54526
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow…
Argo Workflows
3.7.15 / 4.0.6+
HIGH 8.1
CVE-2026-46353
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUr…
Patch available
MEDIUM 6.3
CVE-2026-35148
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form…
Dfx Server
after 2.5
HIGH 8.1
CVE-2026-1609
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…
Build Of Keycloak
No fix yet
MEDIUM 5.8
CVE-2026-62314
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.…
Patch available
HIGH 8.5
CVE-2026-55234
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j…
Patch available
HIGH 7.7
CVE-2026-45313
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc…
Mitigation only
HIGH 8.2
CVE-2026-46485
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated …
Mitigation only
CRITICAL 9.8
CVE-2026-14960
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…
Mitigation only
HIGH 8.8
CVE-2026-20150
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…
Roomos
11.32.6.0 / 11.39.1.1+
HIGH 7.7
CVE-2026-47164
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only…
Patch available
MEDIUM 6.5
CVE-2026-36035
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat…
Mitigation only
HIGH 8.8
CVE-2026-47301
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Configuration Manager 2503
Mitigation only
CRITICAL 9.8
CVE-2026-58617
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
2.111.4+
MEDIUM 5.5
CVE-2026-58545
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-57088
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.20348.5386+
MEDIUM 5.4
CVE-2026-56157
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.5
CVE-2026-50495
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+