Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-35276
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are …
Peoplesoft Enterprise Pt Peopletools
Mitigation only
HIGH 8.8
CVE-2026-35265
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0…
Identity Manager
Mitigation only
HIGH 8.8
CVE-2026-35267
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12…
Identity Manager
Mitigation only
HIGH 8.8
CVE-2026-0647
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated att…
Mitigation only
HIGH 7.5
CVE-2018-25437
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive b…
No fix yet
CRITICAL 9.8
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)…
Mitigation only
HIGH 7.5
CVE-2026-53868
Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without veri…
Mitigation only
HIGH 8.7
CVE-2026-50287
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport whe…
Mitigation only
HIGH 7.6
CVE-2026-53981
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticate…
Patch available
CRITICAL 9.8
CVE-2026-50085
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authent…
Board Service
Mitigation only
MEDIUM 5.3
CVE-2026-50082
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of…
Cloud Developer Portal
No fix yet
MEDIUM 5.3
CVE-2026-8694
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI spec…
Powershell Universal
2026.1.7+
MEDIUM 5.3
CVE-2026-11848
The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers…
Mitigation only
CRITICAL 9.4
CVE-2026-11535
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’…
No fix yet
HIGH 7.7
CVE-2026-50245
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still ima…
Mitigation only
CRITICAL 9.4
CVE-2026-49973
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial…
Patch available
CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…
Peoplesoft Enterprise Peopletools
Mitigation only
HIGH 8.8
CVE-2026-46612
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
CRITICAL 9.8
CVE-2026-20253 KEVEPSS 97%
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug…
Splunk
10.0.7 / 10.2.4+
HIGH 8.3
CVE-2026-45567
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypa…
Mitigation only
HIGH 7.8
CVE-2026-9045
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows…
Mitigation only
HIGH 7.1
CVE-2026-8335
A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries…
Mitigation only
HIGH 8.1
CVE-2026-53469
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route,…
Migration Assessment
0.13.5+
HIGH 7.8
CVE-2026-50512
Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.21.6.0+
HIGH 8.0
CVE-2026-9212
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin…
Lbr1020 Firmware
1.0.4.96 / 1.0.5.50+
MEDIUM 6.8
CVE-2026-50507EPSS 5%
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
CRITICAL 9.8
CVE-2023-54352
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading ma…
Mitigation only
HIGH 7.5
CVE-2023-54350
WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to …
No fix yet
CRITICAL 10.0
CVE-2026-11429
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi…
Mitigation only