Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-44058
An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the a…
Mitigation only
HIGH 8.7
CVE-2026-40165
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentica…
Patch available
MEDIUM 5.3
CVE-2026-2812
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit…
Arcgis Server
after 12.0
MEDIUM 6.0
CVE-2026-9084
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the l…
Patch available
HIGH 8.8
CVE-2026-6456
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `reme…
Mitigation only
CRITICAL 9.8
CVE-2026-36829
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…
Mitigation only
CRITICAL 9.8
CVE-2026-45434EPSS 22%
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBi…
Ofbiz
24.09.06+
MEDIUM 5.3
CVE-2026-31387
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to versio…
Ofbiz
24.09.06+
CRITICAL 10.0
CVE-2026-42822
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
Azure Local
2604.2.25645+
MEDIUM 5.3
CVE-2026-8737
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com…
Mitigation only
CRITICAL 9.1
CVE-2026-44551
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d…
Open Webui
0.9.0+
CRITICAL 9.8
CVE-2026-5229
The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trustin…
Patch available
HIGH 8.8
CVE-2026-8621
Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or or…
Patch available
CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …
Catalyst Sd Wan Manager
20.9.9.1 / 20.12.5.4+
CRITICAL 9.8
CVE-2026-8181EPSS 15%
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypas…
Mitigation only
HIGH 7.5
CVE-2026-44478
hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboard…
Mitigation only
HIGH 8.1
CVE-2026-42602
azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows an…
Opentelemetry Collector Contrib
after 0.150.0
CRITICAL 9.1
CVE-2026-44351
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-re…
Mitigation only
HIGH 7.1
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t…
Grafana
11.6.14 / 12.2.8+
CRITICAL 9.6
CVE-2026-44547
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged a…
Patch available
HIGH 7.5
CVE-2026-42855
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer D…
Arduino Esp32
3.3.8+
HIGH 7.6
CVE-2026-44166
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of th…
Pocketbase
0.22.42 / 0.37.4+
CRITICAL 9.1
CVE-2026-44196
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows …
Mitigation only
CRITICAL 9.1
CVE-2026-33117
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…
Azure Sdk For Java
4.10.6+
HIGH 7.3
CVE-2026-8321
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware…
Mitigation only
CRITICAL 10.0
CVE-2026-42869
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …
Patch available
CRITICAL 9.8
CVE-2026-8305
A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…
Openclaw
2026.2.12+
MEDIUM 5.3
CVE-2026-8244
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI In…
Mitigation only
HIGH 7.3
CVE-2026-8216
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAct…
Mitigation only
MEDIUM 5.3
CVE-2026-8214
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. …
Mitigation only