Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-1061
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/…
Teamwork Management System
after 2.28.0
MEDIUM 5.4
CVE-2026-1009
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An …
Altium Live
Mitigation only
MEDIUM 6.5
CVE-2026-23494
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side aut…
Pimcore
11.5.14 / 12.3.1+
MEDIUM 5.4
CVE-2026-23496
Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se…
Web2print Tools
5.2.2 / 6.1.1+
HIGH 8.8
CVE-2025-61973
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can repla…
Mitigation only
HIGH 7.5
CVE-2025-64516
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any …
Glpi
10.0.21 / 11.0.3+
CRITICAL 9.1
CVE-2026-22909
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential…
Tdc X401gl Firmware
Mitigation only
HIGH 7.5
CVE-2026-21889
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access contro…
Weblate
5.15.2+
HIGH 8.5
CVE-2025-14338
Polkit authentication dis isabled by default and a race
condition in the Polkit authorization check in versions before v0.69.0 can
lead to the same i…
Mitigation only
MEDIUM 5.3
CVE-2025-68949
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string …
N8n
2.2.0+
HIGH 7.8
CVE-2026-20949
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
365 Apps
No fix yet
HIGH 7.5
CVE-2026-20929
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20839
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2026-20843
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.5
CVE-2026-0386
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
Windows Server 2008
10.0.14393.8783 / 10.0.17763.8276+
CRITICAL 10.0
CVE-2026-0881
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Firefox
147.0+
MEDIUM 5.4
CVE-2026-22033
Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e…
Label Studio
after 1.22.0
CRITICAL 9.8
CVE-2025-15503
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o…
Operation And Maintenance Security Management System
after 3.0.8
MEDIUM 5.5
CVE-2025-46297
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files…
macOS
26.2+
HIGH 7.2
CVE-2025-15495
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the…
Simple Php Cms
No fix yet
HIGH 8.4
CVE-2025-68716
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with …
Ks Wr3600 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-22043
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…
Rustfs
Mitigation only
HIGH 8.1
CVE-2026-21694
Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other u…
Titra
0.99.50+
MEDIUM 5.9
CVE-2025-69220
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file co…
Librechat
Patch available
CRITICAL 9.8
CVE-2026-0643
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re…
House Rental And Property Listing Project
Mitigation only
MEDIUM 6.4
CVE-2025-0980
Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid val…
Mitigation only
MEDIUM 6.5
CVE-2026-21635
An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a…
Unifi Connect Ev Station Lite Firmware
1.6.1+
CRITICAL 9.8
CVE-2025-15448
A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/m…
Javamall
Mitigation only
CRITICAL 9.8
CVE-2026-0577
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file …
Online Product Reservation System
Mitigation only
HIGH 7.1
CVE-2026-21447
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde…
Bagisto
2.3.10+