Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.6
CVE-2026-46409
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…
No fix yet
CRITICAL 9.8
CVE-2026-61808
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with…
No fix yet
HIGH 7.1
CVE-2025-71409
Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misl…
No fix yet
CRITICAL 10.0
CVE-2026-63508
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Planetary Computer
No fix yet
HIGH 7.5
CVE-2026-70559
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-…
No fix yet
CRITICAL 9.1
CVE-2026-53984
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's d…
No fix yet
HIGH 7.5
CVE-2026-53977
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by se…
No fix yet
HIGH 7.5
CVE-2026-53985
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler tha…
No fix yet
HIGH 7.3
CVE-2026-18990
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Ro…
No fix yet
CRITICAL 9.6
CVE-2026-71319
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…
No fix yet
HIGH 7.5
CVE-2026-69111
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service compone…
No fix yet
HIGH 7.5
CVE-2026-8446
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_c…
Langflow
1.11.0+
HIGH 7.5
CVE-2026-48911
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing authoriza…
Answer
2.0.2+
CRITICAL 9.8
CVE-2026-71289
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service'…
No fix yet
CRITICAL 9.8
CVE-2026-71262
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersC…
No fix yet
HIGH 7.5
CVE-2026-61891
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/…
Theia
1.74.0+
HIGH 7.5
CVE-2026-71241
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required dec…
No fix yet
HIGH 8.8
CVE-2026-60009
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…
Theia
1.74.0+
HIGH 7.3
CVE-2026-25703
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing …
No fix yet
CRITICAL 9.8
CVE-2026-71214
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS…
No fix yet
MEDIUM 5.3
CVE-2026-71203
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec res…
No fix yet
CRITICAL 9.8
CVE-2026-70552
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access …
No fix yet
HIGH 7.3
CVE-2026-18810
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat…
No fix yet
CRITICAL 9.8
CVE-2026-69703
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated att…
No fix yet
CRITICAL 9.8
CVE-2026-63455
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…
No fix yet
HIGH 8.2
CVE-2026-58071
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator dur…
No fix yet
HIGH 8.1
CVE-2026-24079
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Ar8035 Firmware
No fix yet
CRITICAL 9.8
CVE-2026-61514
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access de…
No fix yet
HIGH 7.8
CVE-2026-59913
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A…
Display And Peripheral Manager
2.3.0.1005+
HIGH 8.1
CVE-2026-67610
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticate…
No fix yet