Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-48899
An improper access check allows privilege escalation through the com_users batch task.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-35223
An improper access check allows unauthorized access to com_config webservice endpoints.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.5
CVE-2026-43934
e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized …
Patch available
HIGH 7.3
CVE-2026-9495
Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently droppe…
Patch available
HIGH 7.3
CVE-2026-9517
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/…
Mitigation only
MEDIUM 6.3
CVE-2026-9445
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the…
Mitigation only
HIGH 7.3
CVE-2026-9421
A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the compo…
Mitigation only
HIGH 8.5
CVE-2026-9489
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…
Mitigation only
MEDIUM 6.3
CVE-2026-9412
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Exec…
No fix yet
MEDIUM 6.3
CVE-2026-9374
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the c…
Mitigation only
MEDIUM 5.3
CVE-2026-9352
A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environm…
No fix yet
MEDIUM 5.3
CVE-2026-9349
A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/…
Mitigation only
HIGH 7.1
CVE-2026-39968
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …
Patch available
HIGH 7.5
CVE-2022-31231
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attac…
Elastic Cloud Storage
3.5.1.7 / 3.6.2.4+
CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…
Unifi Os Server
5.0.8 / 5.1.12+
MEDIUM 5.3
CVE-2026-8240
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealin…
Concrete Cms
9.5.1+
MEDIUM 6.5
CVE-2026-2734
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-…
Mlflow
3.10.0+
HIGH 8.6
CVE-2026-39310
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p…
Mitigation only
HIGH 8.8
CVE-2026-44926
InfoScale CmdServer before 7.4.2 mishandles access control.
Mitigation only
HIGH 7.8
CVE-2026-0856
Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access…
Mitigation only
CRITICAL 10.0
CVE-2026-34234
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is…
Mitigation only
HIGH 8.1
CVE-2026-34358
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multip…
Mitigation only
MEDIUM 5.1
CVE-2026-34390
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient…
Patch available
MEDIUM 6.5
CVE-2026-34233
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints w…
Mitigation only
HIGH 7.3
CVE-2026-39250
An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfa…
Mitigation only
MEDIUM 6.5
CVE-2026-37979
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia…
Build Of Keycloak
26.4.12+
MEDIUM 5.3
CVE-2026-31388
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments.
This issue affects Apache OFBiz: before 24.09.06.
Users are reco…
Ofbiz
24.09.06+
MEDIUM 5.3
CVE-2026-32994
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any auth…
Mitigation only
CRITICAL 9.1
CVE-2023-24215
Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator cred…
Mitigation only
MEDIUM 6.5
CVE-2026-8766
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of t…
Kilo Code Cli
after 7.0.47