Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-4187
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL…
Mitigation only
HIGH 8.1
CVE-2026-3558
Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …
Hue Bridge V2 Firmware
1975170000+
HIGH 7.3
CVE-2026-32594
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the Graph…
Parse Server
8.6.40 / 9.6.0+
MEDIUM 6.3
CVE-2026-2491
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on aff…
Mitigation only
MEDIUM 5.3
CVE-2026-20995
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific con…
Smart Switch
3.7.69.15+
HIGH 7.5
CVE-2017-20222
Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger d…
Sdt Cs3b1 Firmware
No fix yet
HIGH 7.5
CVE-2017-20217
Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows…
No fix yet
HIGH 7.5
CVE-2017-20220
Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the m…
No fix yet
HIGH 7.6
CVE-2026-31944
LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the …
Librechat
No fix yet
HIGH 7.5
CVE-2026-31882
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=…
Dagu
2.2.4+
CRITICAL 9.9
CVE-2026-22192
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m…
Wpdiscuz
7.6.47+
MEDIUM 5.5
CVE-2025-15515
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local netwo…
Easyshare
7.0.11.5+
MEDIUM 6.5
CVE-2025-13778
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;…
Mitigation only
HIGH 8.3
CVE-2025-13779
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;…
Mitigation only
CRITICAL 10.0
CVE-2026-3611EPSS 6%
The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n…
Iq4e Firmware
3.30+
HIGH 8.2
CVE-2026-32231
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the r…
Zeptoclaw
after 0.7.5
CRITICAL 9.8
CVE-2026-31881
Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re…
Runtipi
4.8.0+
HIGH 8.4
CVE-2019-25483
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restric…
No fix yet
HIGH 7.1
CVE-2026-27897
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi…
Vociferous
4.4.2+
HIGH 7.5
CVE-2026-28229
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow …
Argo Workflows
3.7.11 / 4.0.2+
HIGH 7.5
CVE-2026-30933
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incom…
Filebrowser
after 1.2.9
HIGH 7.5
CVE-2026-2339
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I…
Mitigation only
HIGH 7.5
CVE-2026-23662
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Azure Iot Explorer
0.15.13+
MEDIUM 5.3
CVE-2026-30885
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with…
Avideo
25.0+
MEDIUM 5.3
CVE-2026-1920
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due t…
Mitigation only
MEDIUM 5.3
CVE-2026-1919
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a mi…
Mitigation only
CRITICAL 9.8
CVE-2026-30824EPSS 36%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid…
Flowise
3.0.13+
HIGH 7.5
CVE-2026-25071
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endp…
Zikestor Sks8310 8x Firmware
after 1.04.b07
HIGH 7.5
CVE-2026-30846
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int…
Wekan
8.33+
CRITICAL 9.8
CVE-2026-26288
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Api.everon.io
Mitigation only