Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-26292
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration tran…
Patch available
HIGH 7.5
CVE-2026-27660
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
Patch available
HIGH 8.1
CVE-2026-22555
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can ex…
Patch available
HIGH 7.5
CVE-2026-24451
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no…
Patch available
HIGH 7.5
CVE-2026-24690
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
Patch available
HIGH 7.5
CVE-2026-25712
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
Patch available
CRITICAL 9.1
CVE-2026-20706
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
Patch available
CRITICAL 9.8
CVE-2026-20896EPSS 62%
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user w…
Patch available
MEDIUM 5.3
CVE-2026-20909
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Patch available
MEDIUM 5.4
CVE-2026-14614
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.8
CVE-2026-26145
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
HIGH 8.8
CVE-2026-55112
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability f…
Unifi Dream Machine Pro Firmware
after 5.1.15
HIGH 8.8
CVE-2026-55114
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Applica…
Unifi Network Application
10.4.57+
CRITICAL 9.8
CVE-2026-55116
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…
Unifi Connect
3.4.20+
HIGH 8.3
CVE-2026-55118
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found…
Unifi Network Application
10.4.57+
HIGH 8.1
CVE-2026-55119
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Applicatio…
Unifi Talk Application
5.2.2+
HIGH 8.6
CVE-2026-54407
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…
Unifi Protect
7.1.83+
CRITICAL 9.8
CVE-2026-54408
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…
Unifi Protect
7.1.83+
CRITICAL 9.1
CVE-2026-54400
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica…
Unifi Access
4.2.29+
CRITICAL 10.0
CVE-2026-50746
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C…
Unifi Connect Application
3.24.20+
HIGH 8.1
CVE-2026-8147
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allo…
Mlflow
3.14.0+
MEDIUM 6.0
CVE-2026-50280
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoin…
Patch available
MEDIUM 6.5
CVE-2026-14155
Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-14156
Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-14061
Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fr…
Chrome
150.0.7871.46+
MEDIUM 6.5
CVE-2026-14035
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive inform…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-13954
Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-13964
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrict…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-13949
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensit…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-13953
Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process …
Chrome
150.0.7871.47+