Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.3
CVE-2026-10283
A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a mani…
Patch available
HIGH 8.1
CVE-2026-45156
Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a …
Patch available
HIGH 7.3
CVE-2026-10243
A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint…
Mitigation only
HIGH 7.3
CVE-2026-10167
A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impa…
Mitigation only
HIGH 7.3
CVE-2026-10157
A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP Path…
Patch available
HIGH 7.5
CVE-2026-46579
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…
Openshift Container Platform
Mitigation only
CRITICAL 9.8
CVE-2026-49197
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai…
Predator Connect W6x Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-3655
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This…
Mitigation only
CRITICAL 10.0
CVE-2026-46840
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit…
Rest Data Services
after 26.1.0
HIGH 8.8
CVE-2026-46827
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…
E Business Suite
after 12.2.15
CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…
E Business Suite
after 12.2.15
HIGH 7.4
CVE-2026-48526
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric …
Pyjwt
2.13.0+
CRITICAL 9.3
CVE-2026-8979
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the …
Mitigation only
MEDIUM 6.9
CVE-2026-44720
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified …
Mitigation only
HIGH 7.9
CVE-2026-44711
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena…
Mitigation only
HIGH 7.1
CVE-2026-47272
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only …
Mitigation only
HIGH 7.4
CVE-2026-44460
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla…
Mitigation only
MEDIUM 5.5
CVE-2025-68712
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. A…
Mitigation only
CRITICAL 9.1
CVE-2026-7876
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …
Aspera High Speed Transfer Server For Cloud Pak For Integration
1.5.20+
HIGH 8.1
CVE-2026-8994
The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()…
Mitigation only
HIGH 7.5
CVE-2026-44847
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is acces…
Mitigation only
CRITICAL 9.3
CVE-2026-47202
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to r…
Mitigation only
MEDIUM 6.8
CVE-2026-44707
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentic…
Patch available
HIGH 7.5
CVE-2026-48896
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-48897
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 5.6
CVE-2026-9371
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.t…
Mitigation only
CRITICAL 9.8
CVE-2026-47280
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
Azure Resource Manager
No fix yet
HIGH 8.1
CVE-2026-41076
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authe…
No fix yet
MEDIUM 6.5
CVE-2026-39969
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/…
Mitigation only
CRITICAL 9.8
CVE-2026-32253
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…
Sunshine
2026.516.143833+