Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-13329
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action th…
No fix yet
MEDIUM 5.3
CVE-2026-12966
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several …
No fix yet
MEDIUM 6.5
CVE-2026-45377
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_…
No fix yet
CRITICAL 9.8
CVE-2026-52134
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured G…
No fix yet
MEDIUM 5.3
CVE-2026-65311
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's …
No fix yet
MEDIUM 6.5
CVE-2026-14834
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers …
No fix yet
HIGH 8.5
CVE-2026-62246
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user,…
No fix yet
CRITICAL 10.0
CVE-2026-66803
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Azure Cosmos Db
No fix yet
HIGH 7.5
CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an atta…
No fix yet
HIGH 7.3
CVE-2026-16527
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacke…
No fix yet
MEDIUM 5.3
CVE-2026-15250
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its p…
No fix yet
MEDIUM 5.9
CVE-2026-11782
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update actio…
No fix yet
MEDIUM 6.2
CVE-2026-17996
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17986
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proce…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17917
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary ac…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17873
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary ac…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17825
Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary acc…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17830
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrict…
Chrome
151.0.7922.72+
MEDIUM 6.5
CVE-2026-17824
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a…
Chrome
151.0.7922.72+
MEDIUM 6.3
CVE-2026-17780
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions…
Chrome
151.0.7922.72+
HIGH 8.3
CVE-2026-67431
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…
No fix yet
CRITICAL 9.8
CVE-2026-65887
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…
Gridbox
2.20.2+
CRITICAL 9.8
CVE-2026-65888
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…
Gridbox
2.20.2+
HIGH 7.5
CVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…
Gridbox
2.20.2+
HIGH 7.5
CVE-2026-65943
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Ro Csvi
9.11.0+
CRITICAL 9.8
CVE-2026-65884
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…
Gridbox
2.20.2+
CRITICAL 9.3
CVE-2026-41920
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.1
CVE-2026-64863
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV…
Mitigation only
MEDIUM 6.5
CVE-2026-7362
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…
Sterling B2b Integrator
after 6.2.2.0_1
HIGH 8.8
CVE-2026-62427
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To manage the syste…
Mitigation only