Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-3192
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of …
Blockchain
No fix yet
MEDIUM 6.2
CVE-2026-27846
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the networ…
Mitigation only
CRITICAL 9.8
CVE-2026-2624
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows…
Antikor Next Generation Firewall
2.0.1301+
HIGH 7.5
CVE-2026-27595
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…
Parse Dashboard
Mitigation only
HIGH 7.5
CVE-2026-26340
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote at…
Smart\+ Firmware
after 1.181.5
HIGH 7.5
CVE-2026-27584
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows…
Actual
26.2.1+
CRITICAL 9.8
CVE-2025-14577
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands…
Ncp Firmware
1.24.0190 / 6.61.0010+
CRITICAL 9.8
CVE-2026-3053
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d…
Dinky
after 1.2.5
CRITICAL 10.0
CVE-2026-23693
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose t…
Mitigation only
CRITICAL 9.1
CVE-2026-27471
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…
Erpnext
15.98.1 / 16.6.1+
HIGH 7.5
CVE-2026-26048
The Wi-Fi router is vulnerable to de-authentication attacks due to the
absence of management frame protection, allowing forged deauthentication
and…
Mitigation only
HIGH 8.2
CVE-2026-24790
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
No fix yet
CRITICAL 9.8
CVE-2025-30410
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Lin…
Mitigation only
HIGH 7.5
CVE-2026-26319
OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept uns…
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2025-8350
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS al…
Mitigation only
MEDIUM 5.3
CVE-2025-14294
The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCoup…
Mitigation only
HIGH 8.4
CVE-2026-27182
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending …
Mitigation only
HIGH 7.7
CVE-2025-1272
The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. Th…
Mitigation only
HIGH 7.5
CVE-2025-70147
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtai…
Online Time Table Generator
No fix yet
CRITICAL 9.4
CVE-2025-70141
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…
Customer Support System
No fix yet
CRITICAL 9.1
CVE-2025-70146
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke…
Online Time Table Generator
No fix yet
CRITICAL 9.8
CVE-2026-1670
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password…
Mitigation only
MEDIUM 6.1
CVE-2025-7706
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I…
Mitigation only
CRITICAL 10.0
CVE-2026-2577
The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require …
Mitigation only
MEDIUM 6.8
CVE-2025-32063
There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a …
Mitigation only
MEDIUM 5.3
CVE-2025-6792
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-js…
Mitigation only
CRITICAL 9.8
CVE-2026-26333
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec…
Verasmart
2022.0+
CRITICAL 9.8
CVE-2026-26190EPSS 37%
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, w…
Milvus
2.5.27 / 2.6.10+
HIGH 8.8
CVE-2025-14349
Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Ac…
Flexcity
1.0.36+
HIGH 7.5
CVE-2026-26055
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (A…
Yoke
after 0.19.0