Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-39393
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.4.0+
CRITICAL 9.1
CVE-2026-5300
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data …
Coolercontrold
4.0.0+
HIGH 7.5
CVE-2026-39363
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve…
Vite
after 8.0.4
MEDIUM 6.5
CVE-2026-35584
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/…
Freescout
1.8.212+
HIGH 7.5
CVE-2026-35523
Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket…
Strawberry Graphql
0.312.3+
CRITICAL 9.8
CVE-2026-22679EPSS 21%
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev…
E Cology
20260312+
MEDIUM 6.5
CVE-2026-1900
The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.
Link Whisper
0.9.1+
MEDIUM 5.3
CVE-2026-35450
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote serv…
Avideo
after 26.0
HIGH 7.3
CVE-2026-5676
A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi…
Mitigation only
MEDIUM 6.1
CVE-2026-26027
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the i…
Glpi
11.0.6+
HIGH 7.3
CVE-2026-5632
A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Perfor…
Mitigation only
HIGH 7.3
CVE-2026-5616
A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-…
Patch available
HIGH 8.1
CVE-2026-4272
Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Sca…
Mitigation only
HIGH 7.5
CVE-2019-25686
Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by s…
Core Ftp
No fix yet
HIGH 7.5
CVE-2019-25678
C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary…
Computing For Good\'s Basic Laboratory Information System
after 3.4
HIGH 7.5
CVE-2018-25246
Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized inpu…
No fix yet
HIGH 7.5
CVE-2018-25241
VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversize…
No fix yet
CRITICAL 9.1
CVE-2026-34952
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent …
Praisonai
4.5.97+
HIGH 7.5
CVE-2026-32646
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
Cloud Api
2.12.2026+
HIGH 7.5
CVE-2026-28766
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
Cloud Api
2.12.2026+
MEDIUM 5.3
CVE-2026-28767
A specific administrative endpoint notifications is accessible without proper authentication.
Cloud Api
2.12.2026+
CRITICAL 9.8
CVE-2026-0545
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…
Mlflow
Mitigation only
HIGH 7.5
CVE-2026-32211
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
Azure Web Apps
Mitigation only
HIGH 8.6
CVE-2025-15620
HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that…
Hios Switch
09.4.05 / 10.3.01+
CRITICAL 9.8
CVE-2026-35053
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio…
Oneuptime
10.0.42+
CRITICAL 9.1
CVE-2026-34758
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu…
Oneuptime
10.0.40+
HIGH 7.5
CVE-2026-33951
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthent…
Signal K Server
2.24.0+
HIGH 7.5
CVE-2026-29132
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and r…
Secure Email Gateway
15.0.3+
HIGH 7.3
CVE-2026-5320
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of …
Mitigation only
CRITICAL 9.8
CVE-2026-34072
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an …
Cronmaster
2.2.0+