Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-14716
Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue affects GateManager: 11.4;0.
Mitigation only
HIGH 8.1
CVE-2026-32730
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/…
Apostrophecms
4.28.0+
MEDIUM 5.3
CVE-2026-33042
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user ca…
Parse Server
8.6.49 / 9.6.0+
HIGH 7.3
CVE-2026-2991
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ…
Mitigation only
MEDIUM 6.5
CVE-2026-25937
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of …
Glpi
11.0.6+
MEDIUM 5.6
CVE-2026-4349
A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of t…
Mitigation only
CRITICAL 9.8
CVE-2026-4252
A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The mani…
Ac8 Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-4187
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL…
Mitigation only
MEDIUM 6.5
CVE-2026-21004
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
Smart Switch
3.7.69.15+
HIGH 7.1
CVE-2026-32246
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (pas…
Tinyauth
after 5.0.2
CRITICAL 9.8
CVE-2026-32136
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic…
Adguardhome
0.107.73+
CRITICAL 9.8
CVE-2026-1524
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…
Neo4j
5.26.22 / 2026.02+
CRITICAL 9.8
CVE-2026-23813
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote a…
Arubaos Cx
after 10.17.0001
HIGH 8.8
CVE-2026-30967
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth…
Parse Server
8.6.22 / 9.5.2+
HIGH 8.8
CVE-2026-30949
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keyclo…
Parse Server
8.6.18 / 9.5.2+
CRITICAL 9.8
CVE-2026-29792
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthentic…
Feathers
5.0.42+
HIGH 7.8
CVE-2026-26141
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Azure Automation Hybrid Worker Windows Extension
1.3.74+
HIGH 7.8
CVE-2026-26128
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-24294
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
CRITICAL 9.8
CVE-2026-0953
The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.…
Mitigation only
HIGH 8.2
CVE-2025-68402
FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify()…
Patch available
CRITICAL 9.8
CVE-2026-3794
A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component E…
Doracms
Mitigation only
MEDIUM 6.3
CVE-2026-3739
A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/…
Patch available
CRITICAL 9.8
CVE-2026-30863
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, …
Parse Server
8.6.10 / 9.5.0+
HIGH 8.8
CVE-2026-30851
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not str…
Caddy
2.11.2+
HIGH 8.2
CVE-2026-29193
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypas…
Zitadel
4.12.1+
HIGH 8.8
CVE-2026-30223
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using eith…
Olivetin
3000.11.1+
CRITICAL 9.8
CVE-2026-30831
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an…
Rocket.chat
7.10.8 / 7.11.5+
CRITICAL 9.8
CVE-2026-28514
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an…
Rocket.chat
7.8.6 / 7.9.8+
HIGH 8.0
CVE-2026-28800
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a…
Natro Macro
1.1.0+