Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-31846
Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthentic…
Mitigation only
MEDIUM 5.0
CVE-2026-4582
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionalit…
Mitigation only
HIGH 7.3
CVE-2026-4562
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the …
Mitigation only
MEDIUM 5.0
CVE-2026-2756
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Suc…
Mitigation only
HIGH 7.8
CVE-2019-25568
Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuServi…
Memu
after 6.0.7
MEDIUM 6.5
CVE-2026-32896
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthentica…
Openclaw
2026.2.21+
CRITICAL 9.1
CVE-2026-32064
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…
Openclaw
2026.2.21+
HIGH 7.5
CVE-2026-33231
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…
Nltk
after 3.9.3
HIGH 7.5
CVE-2026-33203
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when…
Siyuan
3.6.2+
CRITICAL 9.8
CVE-2026-29796
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Eparking.fi
Mitigation only
CRITICAL 9.8
CVE-2026-25192
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Charge Portal
Mitigation only
CRITICAL 9.8
CVE-2026-22898
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi…
Qvr Pro
2.7.4.1485+
MEDIUM 6.3
CVE-2026-4476
A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown function of the file home/web/ip…
Mitigation only
HIGH 8.1
CVE-2026-33038
WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/chec…
Avideo
26.0+
CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…
Langflow
1.8.2+
CRITICAL 9.8
CVE-2026-21992
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager produc…
Identity Manager
Mitigation only
CRITICAL 9.8
CVE-2026-32985
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t…
Xerte Online Toolkits
after 3.14.0
HIGH 8.1
CVE-2026-22731
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authe…
Spring Boot
3.4.15 / 3.5.12+
HIGH 7.8
CVE-2026-32041
OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain…
Openclaw
2026.3.1+
CRITICAL 9.1
CVE-2025-71257EPSS 5%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…
Footprints
after 20.24.01.001
HIGH 7.8
CVE-2026-24062
The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client c…
Mitigation only
HIGH 8.1
CVE-2026-2603
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…
Build Of Keycloak
26.2.14 / 26.4.10+
MEDIUM 6.8
CVE-2026-22174
OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local pr…
Openclaw
2026.2.22+
MEDIUM 6.5
CVE-2026-1264
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…
Sterling B2b Integrator
6.1.2.8 / 6.2.0.5_2+
HIGH 7.5
CVE-2026-22727
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user …
Mitigation only
CRITICAL 9.8
CVE-2026-3207
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Bpm Enterprise
4.3.5+
HIGH 7.5
CVE-2026-32297
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified con…
Es3 Kvm Firmware
Mitigation only
MEDIUM 6.8
CVE-2026-32291
The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the d…
Comet Gl Rm1 Firmware
1.8.2+
HIGH 8.2
CVE-2026-32296
Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network …
Mitigation only
CRITICAL 9.8
CVE-2026-4312
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces…
Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software
Mitigation only