Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-14348
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to auth…
Mitigation only
HIGH 8.8
CVE-2026-1193
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View…
Mineadmin
No fix yet
HIGH 8.8
CVE-2026-1141
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the…
News Portal
No fix yet
HIGH 8.1
CVE-2026-1112
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public…
Publiccms
after 5.202506.d
MEDIUM 5.4
CVE-2026-1106
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control…
Chamilo Lms
2.0.0+
HIGH 8.0
CVE-2026-20960
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Power Apps
3.25121+
CRITICAL 9.9
CVE-2026-22252
LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida…
Librechat
Patch available
HIGH 8.8
CVE-2026-22042
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `E…
Rustfs
No fix yet
MEDIUM 5.1
CVE-2025-67603
A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? …
Mitigation only
CRITICAL 9.1
CVE-2025-61781
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…
Opencti
6.8.1+
HIGH 8.8
CVE-2026-0574
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file…
Warehouse
after 2025-10-06
HIGH 7.5
CVE-2025-15126
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position…
Jeecg Boot
after 3.9.0
HIGH 8.1
CVE-2025-15085
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/…
Youlai Mall
Mitigation only
HIGH 8.8
CVE-2025-68481
FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login…
Fastapi Users
15.0.2+
MEDIUM 6.3
CVE-2025-14546
Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth sta…
Patch available
CRITICAL 9.8
CVE-2025-65041
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Partner Center
Mitigation only
MEDIUM 6.3
CVE-2025-14889
A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admi…
Advanced Voting Management System
No fix yet
MEDIUM 5.4
CVE-2025-46296
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …
Filemaker Server
22.0.4+
CRITICAL 9.8
CVE-2023-53895
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization throug…
Pimp My Log
Mitigation only
MEDIUM 6.5
CVE-2025-65782
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …
Wekan
after 8.15
MEDIUM 5.5
CVE-2025-46289
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app m…
macOS
14.8.3 / 15.7.3+
MEDIUM 6.7
CVE-2025-40830
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization c…
Sinec Security Monitor
4.10.0+
HIGH 7.5
CVE-2025-14206
A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/…
Online Student Clearance System
No fix yet
MEDIUM 5.3
CVE-2025-12720
The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the ha…
Mitigation only
MEDIUM 5.4
CVE-2025-12505
The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not prop…
Mitigation only
MEDIUM 6.3
CVE-2025-14089
A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ …
Mitigation only
MEDIUM 6.3
CVE-2025-14088
A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This mani…
No fix yet
HIGH 8.1
CVE-2025-14016
A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele…
Mall Swarm
after 1.0.3
CRITICAL 9.8
CVE-2025-58386
In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.…
Terminalfour
8.4.1.2+
CRITICAL 9.6
CVE-2025-66301
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /…
Grav
1.8.0+