Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.9
CVE-2026-44986
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from …
Mitigation only
CRITICAL 9.3
CVE-2026-61740
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN…
Mitigation only
HIGH 8.2
CVE-2026-61435
PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) wh…
Mitigation only
HIGH 8.6
CVE-2026-61436
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.receiv…
Mitigation only
HIGH 8.1
CVE-2026-12281
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treatin…
Mitigation only
CRITICAL 9.8
CVE-2026-5270
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue…
Mitigation only
CRITICAL 9.1
CVE-2026-45363
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'H…
Mitigation only
MEDIUM 5.3
CVE-2026-45754
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma…
Symfony
6.4.40 / 7.4.12+
HIGH 8.0
CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-56169
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2606+
MEDIUM 6.5
CVE-2026-56185
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Windows Admin Center
2511+
HIGH 7.8
CVE-2026-57107
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2606+
HIGH 8.2
CVE-2026-50338
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Azure Spring Cloud
7.3.0+
HIGH 8.7
CVE-2026-22099
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive informat…
Mitigation only
HIGH 7.3
CVE-2026-15557
A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/r…
Mitigation only
HIGH 7.3
CVE-2026-15542
A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket …
Patch available
HIGH 7.3
CVE-2026-15491
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul…
No fix yet
MEDIUM 5.9
CVE-2026-15087
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
No fix yet
CRITICAL 9.1
CVE-2026-15089
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
No fix yet
CRITICAL 10.0
CVE-2026-57216
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c…
Rabbitmq Server
4.2.6+
CRITICAL 9.8
CVE-2026-12761
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …
Mitigation only
HIGH 8.1
CVE-2026-55377
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active …
Patch available
CRITICAL 9.6
CVE-2026-59151
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de…
Patch available
HIGH 7.4
CVE-2026-55672
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device …
Patch available
HIGH 8.3
CVE-2026-56675
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s…
Patch available
MEDIUM 6.5
CVE-2026-56312
Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha valid…
Mitigation only
HIGH 8.1
CVE-2026-12595
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. …
Mitigation only
HIGH 8.1
CVE-2026-12597
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3.…
Mitigation only
HIGH 8.1
CVE-2026-12598
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login add…
Mitigation only
HIGH 8.1
CVE-2026-55689
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation whe…
Helm Charts
0.3.9 / 1.18.0+