Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2026-48610
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certai…
Mitigation only
HIGH 7.2
CVE-2026-47366
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated admini…
Mitigation only
HIGH 8.1
CVE-2026-44249
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15…
Netty
4.1.135 / 4.2.15+
HIGH 8.1
CVE-2026-45178
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticate…
Idira Secrets Manager
13.8.1 / 14.2.6+
CRITICAL 9.1
CVE-2026-45177
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauth…
Idira Secrets Manager Edge
1.8+
MEDIUM 5.3
CVE-2025-46308
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may …
Ipados
15.4 / 18.4+
HIGH 7.5
CVE-2025-46315
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user …
macOS
26.1+
MEDIUM 5.5
CVE-2025-43339
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access se…
macOS
26.1+
MEDIUM 5.5
CVE-2025-24165
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…
macOS
13.7.5 / 14.7.5+
HIGH 7.5
CVE-2026-41856
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarch…
Spring For Graphql
1.0.7 / 1.3.9+
CRITICAL 10.0
CVE-2026-46695
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …
Patch available
CRITICAL 9.9
CVE-2026-50545
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
CRITICAL 9.9
CVE-2026-50563
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
CRITICAL 9.9
CVE-2026-50564
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 7.7
CVE-2026-49822
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 7.7
CVE-2026-49823
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 8.5
CVE-2026-49824
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
CRITICAL 9.8
CVE-2026-46614
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
MEDIUM 5.5
CVE-2026-20259
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23…
Splunk
9.3.2411.131 / 10.0.7+
HIGH 7.5
CVE-2026-41728
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when …
Spring Data Rest
3.7.20 / 4.3.17+
MEDIUM 5.3
CVE-2026-41837
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson cu…
Spring Data Rest
3.7.20 / 4.3.17+
HIGH 8.6
CVE-2026-47907
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution …
Dreamweaver
21.8+
HIGH 7.5
CVE-2026-39169
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
Mitigation only
HIGH 8.1
CVE-2026-36720
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
Mitigation only
HIGH 7.8
CVE-2026-49161
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
Pc Manager
3.21.6.0+
HIGH 7.9
CVE-2026-48578
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 6.8
CVE-2026-45658
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.1
CVE-2026-45649
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Excel
No fix yet
HIGH 7.9
CVE-2026-45654
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26100.32995+
HIGH 7.8
CVE-2026-42829
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26200.8655+