Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2026-48115
Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a…
No fix yet
MEDIUM 6.3
CVE-2026-18631
A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr…
No fix yet
MEDIUM 5.4
CVE-2026-18584
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of …
No fix yet
MEDIUM 6.4
CVE-2026-67332
@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens fo…
No fix yet
HIGH 7.7
CVE-2026-14538
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…
Mcp Toolbox For Databases
after 1.4.0
CRITICAL 9.3
CVE-2026-48499
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…
No fix yet
MEDIUM 5.3
CVE-2026-23981
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar…
No fix yet
MEDIUM 6.5
CVE-2026-41187
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,…
Calico
3.21.7 / 3.22.4+
MEDIUM 5.3
CVE-2026-66488
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Gridbox
2.20.2+
MEDIUM 6.5
CVE-2026-18207
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of …
Build Of Keycloak
No fix yet
HIGH 7.1
CVE-2026-47726
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGe…
No fix yet
MEDIUM 6.5
CVE-2026-61487
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
An authenticated low-privilege user can bypas…
Activemq
5.19.9 / 6.2.8+
MEDIUM 6.5
CVE-2026-64743
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6,…
Ipados
26.6+
MEDIUM 5.5
CVE-2026-64711
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8…
Ipados
14.8.8 / 15.7.8+
MEDIUM 6.5
CVE-2026-43792
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to acce…
Safari
26.6+
MEDIUM 5.5
CVE-2026-43775
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be abl…
macOS
15.7.8 / 26.6+
MEDIUM 5.5
CVE-2026-43756
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …
macOS
14.8.8 / 15.7.8+
HIGH 8.2
CVE-2026-64642
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica…
Next.js
16.2.11+
MEDIUM 5.0
CVE-2026-17531
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route…
No fix yet
MEDIUM 6.3
CVE-2026-17529
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The …
No fix yet
MEDIUM 6.3
CVE-2026-17530
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the…
No fix yet
MEDIUM 6.3
CVE-2026-17434
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of t…
No fix yet
MEDIUM 5.3
CVE-2026-17433
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk…
No fix yet
HIGH 7.5
CVE-2026-62835
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Azure Portal
No fix yet
CRITICAL 9.9
CVE-2026-56160
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Azure Red Hat Openshift
No fix yet
MEDIUM 5.4
CVE-2026-62563
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte…
Work In Process
after 12.2.15
MEDIUM 6.1
CVE-2026-62444
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…
E Business Suite
after 12.2.15
MEDIUM 6.5
CVE-2026-61082
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily…
Mysql Connectors
No fix yet
MEDIUM 5.4
CVE-2026-60957
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that ar…
E Business Suite
after 12.2.15
MEDIUM 5.4
CVE-2026-60911
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affect…
Property Manager
after 12.2.15