Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-2754
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote att…
Navbox Firmware
4.16.2.4+
CRITICAL 9.8
CVE-2026-26051
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Mobiliti E Mobi.hu
Mitigation only
HIGH 7.5
CVE-2026-27603
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4…
Chartbrew
4.8.4+
CRITICAL 9.8
CVE-2026-22552
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …
Epower.ie
Mitigation only
CRITICAL 9.8
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service
No fix yet
MEDIUM 5.9
CVE-2026-29613
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests …
Openclaw
2026.2.12+
HIGH 7.8
CVE-2026-28485
OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unautho…
Openclaw
2026.2.12+
MEDIUM 6.5
CVE-2026-29606
OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests…
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2026-28472
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch…
Openclaw
2026.2.2+
HIGH 7.7
CVE-2026-28468
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests witho…
Openclaw
2026.2.14+
MEDIUM 5.4
CVE-2026-28458
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket e…
Openclaw
2026.2.1+
HIGH 8.2
CVE-2026-28450
OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/p…
Openclaw
2026.2.12+
CRITICAL 9.8
CVE-2026-27944EPSS 22%
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and …
Nginx Ui
2.3.3+
CRITICAL 9.8
CVE-2026-23767
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not…
Sb H50 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-27446EPSS 10%
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…
Artemis
after 2.44.0
CRITICAL 9.8
CVE-2026-27012
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authent…
Openstamanager
after 2.9.8
HIGH 8.8
CVE-2026-1775
The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameter…
Mitigation only
CRITICAL 9.0
CVE-2025-30035
The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the…
Mitigation only
HIGH 7.5
CVE-2026-2844
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects T…
Timepictra
after 11.3
MEDIUM 6.5
CVE-2026-28352
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API…
Indico
3.3.11+
CRITICAL 9.8
CVE-2026-27028
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Mobility46.se
Mitigation only
CRITICAL 9.8
CVE-2026-27767
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Swtchenergy.com
Mitigation only
CRITICAL 9.8
CVE-2026-27772
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Ev.energy
Mitigation only
CRITICAL 9.8
CVE-2026-25851
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Chargemap.com
Mitigation only
CRITICAL 9.8
CVE-2026-24731
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Ev2go.io
Mitigation only
CRITICAL 9.8
CVE-2026-20781
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Cloudcharge.se
Mitigation only
HIGH 7.5
CVE-2026-27449
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c…
Mitigation only
CRITICAL 9.8
CVE-2026-22207
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g…
Patch available
HIGH 8.0
CVE-2026-27509
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDD…
Go2 Firmware
after 1.1.9
HIGH 7.0
CVE-2026-3194
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas…
Blockchain
No fix yet