Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-36035
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat…
Mitigation only
HIGH 8.8
CVE-2026-47301
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Configuration Manager 2503
Mitigation only
CRITICAL 9.8
CVE-2026-58617
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
2.111.4+
MEDIUM 5.5
CVE-2026-58545
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-57088
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.20348.5386+
MEDIUM 5.4
CVE-2026-56157
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.5
CVE-2026-50495
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 7.1
CVE-2026-50465
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
HIGH 7.8
CVE-2026-50423
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.7548 / 10.0.19045.7548+
MEDIUM 6.1
CVE-2026-50418
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.20348.5386 / 10.0.26100.8875+
HIGH 7.8
CVE-2026-50373
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 7.8
CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 7.8
CVE-2026-55014
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
Remote Help
5.2.1037.0+
HIGH 8.8
CVE-2026-50342
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26200.8875+
HIGH 7.8
CVE-2026-50351
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50311
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.0
CVE-2026-50325
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.0
CVE-2026-50297
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.0
CVE-2026-49805
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.3
CVE-2026-15677
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a…
Mitigation only
HIGH 8.8
CVE-2026-57855
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/C…
Patch available
CRITICAL 9.1
CVE-2026-51538
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th…
Opener
Mitigation only
MEDIUM 5.3
CVE-2026-15530
A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=…
Mitigation only
HIGH 7.3
CVE-2026-15488
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller…
Patch available
MEDIUM 5.3
CVE-2026-15476
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of …
Mitigation only
MEDIUM 5.3
CVE-2026-15475
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the…
Mitigation only
CRITICAL 9.8
CVE-2026-20744
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
Mitigation only
MEDIUM 6.5
CVE-2026-56335
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration …
Mitigation only
MEDIUM 6.5
CVE-2026-40009
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB.
Authenticated users can escalate to full tree-path access by re…
Mitigation only
HIGH 7.5
CVE-2026-40452
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB.
Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat…
Mitigation only