Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2026-5999
A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulati…
Mitigation only
HIGH 7.3
CVE-2026-5842
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the compo…
Mitigation only
MEDIUM 5.7
CVE-2026-39901
monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated t…
Mitigation only
MEDIUM 6.5
CVE-2026-35407
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found i…
Saleor
3.20.118 / 3.21.54+
HIGH 7.2
CVE-2026-39389
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.4.0+
HIGH 8.8
CVE-2026-35610
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in…
Polarlearn
No fix yet
HIGH 7.3
CVE-2026-5642
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown functio…
Mitigation only
HIGH 7.1
CVE-2017-20238
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows…
Mitigation only
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.4
CVE-2026-33950
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…
Signal K Server
2.24.0+
MEDIUM 5.3
CVE-2026-5326
A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_use…
Mitigation only
HIGH 8.1
CVE-2026-5246
A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co…
Mongoose
7.21+
HIGH 7.7
CVE-2026-34222EPSS 5%
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access …
Open Webui
0.8.11+
MEDIUM 6.5
CVE-2026-5283
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML…
Chrome
146.0.7680.177+
HIGH 7.5
CVE-2026-34784
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, f…
Parse Server
8.6.71 / 9.7.1+
MEDIUM 5.3
CVE-2026-33074
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
MEDIUM 5.4
CVE-2026-32615
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
HIGH 8.1
CVE-2026-4818
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage…
Flx
4.1.0+
MEDIUM 6.5
CVE-2026-1710
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …
Mitigation only
MEDIUM 6.5
CVE-2026-32716
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using …
Scitokens Library
1.9.6+
MEDIUM 5.3
CVE-2026-30878
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form en…
Basercms
5.2.3+
HIGH 8.0
CVE-2026-4248
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to…
Patch available
HIGH 7.3
CVE-2026-4990
A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the compon…
Mitigation only
MEDIUM 6.5
CVE-2026-33954
LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed…
Linkace
2.5.3+
MEDIUM 6.5
CVE-2026-4958
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentSe…
Xagent
No fix yet
HIGH 8.8
CVE-2026-33735
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/impor…
Mytube
1.8.69+
MEDIUM 6.5
CVE-2026-34056
OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in Ope…
Openemr
after 8.0.0.3
MEDIUM 5.4
CVE-2026-34051
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper a…
Openemr
8.0.0.3+
MEDIUM 5.5
CVE-2026-28881
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
macOS
26.4+