Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-30962
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the valida…
Parse Server
8.6.19 / 9.5.2+
CRITICAL 10.0
CVE-2026-30966
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Serv…
Parse Server
8.6.20 / 9.5.2+
MEDIUM 5.3
CVE-2026-2742
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.…
Vaadin
14.14.1 / 23.6.7+
HIGH 7.8
CVE-2026-25176
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-24290
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 7.8
CVE-2026-23660
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2.6.4+
MEDIUM 6.7
CVE-2026-22628
An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system comman…
Fortiswitchaxfixed
1.0.2+
HIGH 8.8
CVE-2026-21262
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6480.4 / 13.0.7075.5+
HIGH 7.1
CVE-2026-30926
SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note …
Siyuan
3.5.10+
HIGH 7.5
CVE-2025-62166
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is …
Freshrss
1.28.0+
HIGH 7.5
CVE-2026-30140
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/Route…
W15e Firmware
Mitigation only
HIGH 8.8
CVE-2026-3800
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?…
Resort Reservation System
No fix yet
HIGH 8.8
CVE-2026-3797
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o…
Video Surveillance System Firmware
Mitigation only
HIGH 7.8
CVE-2026-3796
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library…
Qax Internet Control Gateway
after 2025-10-22
HIGH 8.8
CVE-2026-3748
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/…
Bytedesk
1.4.5.1+
HIGH 8.8
CVE-2026-3749
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav…
Bytedesk
1.4.5.1+
HIGH 8.8
CVE-2026-30855
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass …
Weknora
0.3.2+
MEDIUM 6.5
CVE-2026-30859
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control…
Weknora
0.2.12+
HIGH 7.5
CVE-2026-30244
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…
Plane
1.2.2+
HIGH 7.5
CVE-2025-70363
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive…
Ez Platform
after 2.5.32
MEDIUM 5.0
CVE-2026-29060
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privi…
Gokapi
2.2.3+
MEDIUM 5.4
CVE-2026-29061
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerab…
Gokapi
2.2.3+
MEDIUM 6.4
CVE-2026-28682
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implement…
Gokapi
2.2.3+
MEDIUM 6.5
CVE-2026-25877
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…
Chartbrew
4.8.1+
HIGH 8.1
CVE-2026-29188
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…
Filebrowser
2.61.1+
HIGH 7.1
CVE-2026-29077
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user …
Frappe
14.100.0 / 15.98.0+
HIGH 8.1
CVE-2026-28410
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the to…
Graph Protocol Contracts
3.0.0+
HIGH 8.1
CVE-2025-70614
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing…
Ussd Gateway
Mitigation only
HIGH 7.5
CVE-2026-28790
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…
Olivetin
3000.11.0+
MEDIUM 5.3
CVE-2026-27723
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belongin…
Openproject
17.0.5 / 17.1.2+