Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.3
CVE-2026-8758
A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp.…
Mitigation only
MEDIUM 5.3
CVE-2026-8752
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapid…
H2o
after 7402
HIGH 7.5
CVE-2026-8750
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water…
H2o
after 7402
HIGH 8.1
CVE-2026-45301
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all…
Open Webui
0.3.16+
HIGH 7.1
CVE-2026-44556
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the Ope…
Open Webui
0.9.0+
CRITICAL 9.9
CVE-2026-44774
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant wi…
Traefik
2.11.46 / 3.6.17+
MEDIUM 6.5
CVE-2025-67437
Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.
No fix yet
HIGH 8.8
CVE-2024-36323
Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to th…
Mitigation only
HIGH 8.5
CVE-2026-7373
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When st…
Mitigation only
MEDIUM 5.3
CVE-2025-0040
Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical acce…
Mitigation only
MEDIUM 5.5
CVE-2026-8586
Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control v…
Chrome
148.0.7778.168+
MEDIUM 5.3
CVE-2026-24711
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
Cfengine
3.21.8 / 3.24.3+
HIGH 7.5
CVE-2026-44478
hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboard…
Mitigation only
HIGH 7.1
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t…
Grafana
11.6.14 / 12.2.8+
HIGH 8.1
CVE-2026-33381
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The …
Grafana
11.6.14 / 12.2.8+
CRITICAL 9.1
CVE-2026-44007
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require(…
Vm2
3.11.1+
MEDIUM 6.8
CVE-2026-36738
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks a…
T18 21k Firmware
No fix yet
MEDIUM 5.3
CVE-2026-44341
GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job detai…
Mitigation only
MEDIUM 5.3
CVE-2026-44352
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Bro…
Mitigation only
CRITICAL 9.3
CVE-2026-44225
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every …
Mitigation only
CRITICAL 9.8
CVE-2026-44277
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…
Fortiauthenticator
6.5.7 / 6.6.9+
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
MEDIUM 5.5
CVE-2026-42832
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Excel
16.0.19822.20190+
MEDIUM 5.3
CVE-2026-42177
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a s…
Mitigation only
MEDIUM 6.2
CVE-2026-41614
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
365 Copilot
19.2604.43111.0+
MEDIUM 5.5
CVE-2026-41101
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
Word
16.0.19822.20190+
MEDIUM 5.5
CVE-2026-41102
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
Powerpoint
16.0.19822.20190+
HIGH 8.8
CVE-2026-40420
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2026-41086
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2.6.7+
HIGH 7.8
CVE-2026-40381
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.63+