Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-16867
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…
I
No fix yet
CRITICAL 9.8
CVE-2026-17197
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
I
No fix yet
CRITICAL 10.0
CVE-2026-59500
CWE-287: Improper Authentication
No fix yet
CRITICAL 9.8
CVE-2026-14182
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel…
No fix yet
MEDIUM 5.5
CVE-2026-47718
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid…
No fix yet
CRITICAL 9.1
CVE-2026-73501
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r…
No fix yet
CRITICAL 10.0
CVE-2024-27253
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
No fix yet
HIGH 7.4
CVE-2026-11923
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…
Security Verify Access
No fix yet
HIGH 8.1
CVE-2026-12359
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…
Security Verify Access
No fix yet
HIGH 7.5
CVE-2026-42018
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing …
No fix yet
MEDIUM 5.3
CVE-2026-68760
An unauthenticated user may bypass authentication under specific cache conditions.
No fix yet
CRITICAL 9.4
CVE-2026-50561
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authenti…
No fix yet
CRITICAL 9.8
CVE-2026-26035
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…
No fix yet
MEDIUM 6.1
CVE-2026-17013
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block,…
No fix yet
HIGH 8.1
CVE-2026-18961
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass …
No fix yet
HIGH 8.3
CVE-2026-73241
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an a…
No fix yet
HIGH 7.5
CVE-2026-71467
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ…
No fix yet
MEDIUM 5.3
CVE-2026-73085
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs w…
No fix yet
HIGH 8.8
CVE-2026-62827
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20522+
MEDIUM 6.3
CVE-2026-20891
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg…
No fix yet
HIGH 7.0
CVE-2026-20885
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and es…
No fix yet
MEDIUM 6.7
CVE-2026-20752
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software ad…
No fix yet
CRITICAL 9.8
CVE-2026-12571
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
No fix yet
HIGH 8.2
CVE-2026-72922
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's…
No fix yet
CRITICAL 9.8
CVE-2026-51584
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route…
No fix yet
HIGH 7.5
CVE-2026-72746
FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, t…
No fix yet
HIGH 8.8
CVE-2026-72533
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization …
No fix yet
MEDIUM 5.9
CVE-2026-72917
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, Any…
No fix yet
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
No fix yet
HIGH 8.1
CVE-2026-18468
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the pa…
No fix yet