Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-18469
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying bo…
No fix yet
HIGH 8.8
CVE-2026-18786
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the …
No fix yet
MEDIUM 5.4
CVE-2026-18960
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who hol…
No fix yet
CRITICAL 9.8
CVE-2026-16299
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to r…
No fix yet
HIGH 8.2
CVE-2026-16257
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can b…
No fix yet
HIGH 8.1
CVE-2026-13600
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator a…
No fix yet
HIGH 7.3
CVE-2026-19342
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Log…
No fix yet
CRITICAL 9.8
CVE-2026-15038
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot…
No fix yet
MEDIUM 5.3
CVE-2026-16282
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser…
No fix yet
CRITICAL 9.1
CVE-2026-48039
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat…
No fix yet
CRITICAL 9.8
CVE-2026-56793
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with…
Openmanage Server Administrator
11.1.0.2+
HIGH 8.1
CVE-2026-16030
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-base…
No fix yet
CRITICAL 9.8
CVE-2026-14205
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price…
No fix yet
CRITICAL 9.6
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure Sql Database
No fix yet
HIGH 8.1
CVE-2026-64665
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that …
No fix yet
CRITICAL 9.8
CVE-2026-65400 KEV
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…
macOS
14.8.9 / 15.7.9+
CRITICAL 9.8
CVE-2026-48087
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration …
No fix yet
MEDIUM 5.3
CVE-2026-14547
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its p…
No fix yet
HIGH 8.1
CVE-2026-15459
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet conn…
No fix yet
HIGH 7.3
CVE-2026-18990
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Ro…
No fix yet
CRITICAL 9.8
CVE-2026-9192
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote …
No fix yet
CRITICAL 9.1
CVE-2026-71277
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never …
No fix yet
HIGH 7.5
CVE-2026-15372
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, …
No fix yet
HIGH 7.5
CVE-2026-16036
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the t…
No fix yet
HIGH 7.5
CVE-2026-16055
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an…
No fix yet
CRITICAL 9.1
CVE-2026-15210
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate…
No fix yet
MEDIUM 5.0
CVE-2026-18816
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_…
No fix yet
HIGH 8.1
CVE-2026-70482
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True,…
No fix yet
HIGH 7.3
CVE-2026-18810
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat…
No fix yet