Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2026-28787
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no…
Oneuptime
after 10.0.11
MEDIUM 5.3
CVE-2026-28428
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validatio…
Talishar
2026-02-22+
CRITICAL 9.8
CVE-2026-29093
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…
Avideo
24.0+
MEDIUM 5.3
CVE-2026-28471
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching …
Openclaw
2026.2.2+
CRITICAL 9.8
CVE-2026-3224
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate…
Devolutions Server
2025.3.16.0+
CRITICAL 9.8
CVE-2026-24898
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis…
Openemr
8.0.0+
CRITICAL 9.8
CVE-2026-23600
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
Autopass License Server
9.19+
CRITICAL 9.8
CVE-2026-28408
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…
Wegia
3.6.5+
HIGH 8.8
CVE-2026-27939
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…
Statamic
6.4.0+
MEDIUM 5.3
CVE-2026-1305
The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a…
Mitigation only
CRITICAL 9.1
CVE-2026-28215
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…
Hoppscotch
2026.2.0+
HIGH 8.2
CVE-2025-71057
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via s…
Mitigation only
MEDIUM 6.5
CVE-2026-26077
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, M…
Discourse
2025.12.0 / 2026.1.1+
HIGH 7.0
CVE-2026-3194
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas…
Blockchain
No fix yet
HIGH 8.1
CVE-2026-3192
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of …
Blockchain
No fix yet
CRITICAL 9.8
CVE-2026-20129
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
MEDIUM 6.5
CVE-2026-27611
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protecte…
Filebrowser Quantum
1.1.3 / 1.2.6+
HIGH 7.5
CVE-2026-24241
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication is…
Delegated License Service
3.1.8 / 3.6.0+
CRITICAL 9.8
CVE-2026-3053
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d…
Dinky
after 1.2.5
CRITICAL 9.1
CVE-2026-27197
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML…
Sentry
26.2.0+
HIGH 8.1
CVE-2026-27134
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.…
Strimzi Kafka Operator
0.50.1+
CRITICAL 9.4
CVE-2025-70833
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra…
Smanga
Mitigation only
MEDIUM 6.9
CVE-2025-41023
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanism…
No fix yet
CRITICAL 10.0
CVE-2025-15586
OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in …
Patch available
MEDIUM 5.3
CVE-2025-7630
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and T…
Mitigation only
HIGH 7.5
CVE-2026-1368
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unaut…
Mitigation only
HIGH 8.8
CVE-2026-26119
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2511+
HIGH 7.5
CVE-2026-25748
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication whe…
Authentik
2025.10.4 / 2025.12.4+
HIGH 8.8
CVE-2026-25922
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser…
Authentik
2025.8.6 / 2025.10.4+