Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-39310
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p…
Mitigation only
CRITICAL 10.0
CVE-2026-20223
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…
Secure Workload
3.10.8.3 / 4.0.3.17+
CRITICAL 9.1
CVE-2026-8602
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req…
Scadabr
Mitigation only
MEDIUM 6.5
CVE-2026-8706
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs …
Firefox
151.0+
CRITICAL 9.1
CVE-2026-31071
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit…
Mitigation only
CRITICAL 9.8
CVE-2018-25335
WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by…
Mitigation only
CRITICAL 9.8
CVE-2018-25332
GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting we…
Gitbucket
4.24.0+
MEDIUM 5.3
CVE-2026-8737
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com…
Mitigation only
MEDIUM 5.3
CVE-2026-45397
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns liv…
Open Webui
0.9.5+
MEDIUM 5.3
CVE-2026-45248
Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthent…
Guardian
after 3.5.1
CRITICAL 9.4
CVE-2026-44592
Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone …
Mitigation only
HIGH 7.8
CVE-2026-42283
DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connec…
Devspace
Mitigation only
MEDIUM 6.3
CVE-2025-62619
Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensiti…
Mitigation only
HIGH 7.3
CVE-2025-27853
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authenti…
Empirbus Wireless Display Unit Firmware
Mitigation only
HIGH 7.8
CVE-2026-0247
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication c…
Prisma Access Agent
26.2.1+
HIGH 8.8
CVE-2026-42289
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely …
Mitigation only
MEDIUM 6.1
CVE-2026-42303
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification …
Patch available
MEDIUM 5.3
CVE-2026-31245
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unau…
Mem0
Mitigation only
HIGH 7.5
CVE-2026-31240
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating me…
Mitigation only
MEDIUM 6.5
CVE-2026-31241
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows un…
Mem0
Mitigation only
CRITICAL 9.1
CVE-2026-31242
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin…
Mem0
Mitigation only
MEDIUM 6.5
CVE-2026-31243
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DEL…
Mem0
Mitigation only
MEDIUM 6.5
CVE-2026-31244
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoi…
Mem0
Mitigation only
HIGH 8.7
CVE-2026-5029
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC end…
Mitigation only
CRITICAL 9.1
CVE-2026-22924
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated con…
Simatic Cn 4100 Firmware
5.0+
MEDIUM 5.3
CVE-2026-43881
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that dis…
Patch available
CRITICAL 9.9
CVE-2026-42864
FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha…
Mitigation only
HIGH 7.5
CVE-2026-44413
In JetBrains TeamCity before 2026.1
2025.11.5 authenticated users could expose server API to unauthorised access
Teamcity
2025.11.5+
HIGH 8.7
CVE-2026-42856
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no auth…
Mitigation only
MEDIUM 6.8
CVE-2026-42312
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE…
Pyload Ng
0.5.0b3.dev100+