Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2026-18969
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi…
No fix yet
HIGH 8.1
CVE-2025-63822
SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters t…
No fix yet
MEDIUM 5.4
CVE-2026-70612
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…
No fix yet
HIGH 8.1
CVE-2026-10547
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing…
Langflow
1.11.0+
CRITICAL 9.9
CVE-2026-20304
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…
No fix yet
CRITICAL 9.0
CVE-2026-20267
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…
Ios Xe
No fix yet
MEDIUM 6.3
CVE-2026-18927
A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057…
No fix yet
MEDIUM 6.6
CVE-2026-70602
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…
No fix yet
HIGH 8.1
CVE-2026-16102
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f…
Build Of Keycloak
26.4.14 / 26.6.5+
HIGH 7.5
CVE-2025-70962
Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication me…
No fix yet
MEDIUM 6.2
CVE-2026-71204
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application setti…
No fix yet
HIGH 7.5
CVE-2026-16736
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrat…
No fix yet
HIGH 8.1
CVE-2026-15230
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, a…
No fix yet
CRITICAL 9.1
CVE-2026-67979
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary …
No fix yet
MEDIUM 5.4
CVE-2026-70481
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an…
No fix yet
HIGH 8.3
CVE-2026-70476
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa…
No fix yet
HIGH 7.3
CVE-2026-18788
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager…
No fix yet
MEDIUM 5.9
CVE-2026-16547
The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does…
No fix yet
MEDIUM 6.5
CVE-2026-14816
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording…
No fix yet
MEDIUM 5.4
CVE-2026-14848
The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription…
No fix yet
HIGH 7.5
CVE-2026-67970
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
No fix yet
HIGH 7.5
CVE-2026-67975
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add…
No fix yet
HIGH 7.8
CVE-2026-59912
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged atta…
Display And Peripheral Manager
2.3.0.1005+
MEDIUM 6.2
CVE-2026-15430
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …
No fix yet
MEDIUM 5.3
CVE-2026-56608
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…
Icontrol
No fix yet
MEDIUM 6.5
CVE-2026-16563
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through i…
No fix yet
HIGH 7.5
CVE-2026-15241
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing …
No fix yet
HIGH 7.5
CVE-2026-15151
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users …
No fix yet
MEDIUM 6.5
CVE-2026-14315
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing una…
No fix yet
MEDIUM 5.3
CVE-2026-14822
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endp…
No fix yet