Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-47212
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP…
Symfony
6.4.40 / 7.4.12+
MEDIUM 5.3
CVE-2026-45754
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma…
Symfony
6.4.40 / 7.4.12+
MEDIUM 5.3
CVE-2026-45755
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::…
Symfony
7.4.12 / 8.0.12+
HIGH 7.8
CVE-2026-50451
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges …
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-50444
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-57969
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Azure Cyclecloud
8.9.1+
CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 7.8
CVE-2026-50333
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.1
CVE-2026-49174
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
CRITICAL 10.0
CVE-2026-10577
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce…
Mitigation only
CRITICAL 9.8
CVE-2026-62422
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct…
Youtrack
2024.2.148429 / 2024.3.148430+
CRITICAL 9.1
CVE-2026-58319
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …
Doris
3.1.0+
HIGH 8.9
CVE-2026-15416
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network acces…
Patch available
CRITICAL 9.1
CVE-2026-62327
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP…
Mitigation only
CRITICAL 9.8
CVE-2026-59801
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API…
Mitigation only
CRITICAL 9.3
CVE-2026-6847
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos…
Mitigation only
CRITICAL 9.3
CVE-2026-22096
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or up…
Mitigation only
HIGH 7.3
CVE-2026-15491
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul…
No fix yet
CRITICAL 9.2
CVE-2026-55884
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on…
Patch available
MEDIUM 5.3
CVE-2026-57475
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make lim…
Ai Assist For Customer
2026-03-25+
HIGH 8.3
CVE-2026-56675
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s…
Patch available
HIGH 7.5
CVE-2026-38059
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can …
Mitigation only
HIGH 7.5
CVE-2026-40006
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne…
Mitigation only
CRITICAL 9.8
CVE-2026-58123
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell …
Patch available
MEDIUM 5.3
CVE-2026-55605
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku…
Mitigation only
HIGH 8.8
CVE-2026-59148
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th…
Patch available
HIGH 7.2
CVE-2026-0283
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with networ…
Pan Os
10.2.7 / 10.2.10+
MEDIUM 5.3
CVE-2026-61344
The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder record…
Mitigation only
CRITICAL 10.0
CVE-2026-59726
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp…
Patch available
MEDIUM 6.5
CVE-2026-59715
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured w…
Open Webui
0.10.0+