Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-26235
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the s…
Smart Visu Server Firmware
after 1.1.1050
CRITICAL 9.8
CVE-2026-1729
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not p…
Mitigation only
CRITICAL 9.8
CVE-2026-24789
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Mitigation only
CRITICAL 9.8
CVE-2026-25084
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
Mitigation only
CRITICAL 9.8
CVE-2026-2248
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …
Mitigation only
CRITICAL 9.8
CVE-2026-2249
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …
Mitigation only
CRITICAL 9.8
CVE-2025-8025
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func…
Mitigation only
HIGH 7.5
CVE-2026-1603 KEVEPSS 81%
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…
Endpoint Manager
2024+
CRITICAL 9.8
CVE-2026-25938
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…
Fuxa
1.2.11+
CRITICAL 9.8
CVE-2026-25895
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at…
Fuxa
1.2.10+
HIGH 7.5
CVE-2026-25885
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can …
Polarlearn
Patch available
MEDIUM 5.3
CVE-2026-25878
FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin au…
Froshadminer
2.2.1+
HIGH 7.5
CVE-2026-25791
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP boo…
Sliver
1.7.0+
CRITICAL 9.8
CVE-2026-25848
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Hub
2025.3.119807+
CRITICAL 9.1
CVE-2026-2234
C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail …
Mitigation only
CRITICAL 9.8
CVE-2026-2165
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.p…
E Commerce
Mitigation only
HIGH 7.5
CVE-2020-37146
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive config…
No fix yet
HIGH 7.5
CVE-2020-37157
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials thro…
No fix yet
HIGH 8.4
CVE-2026-25593
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via conf…
Openclaw
2026.1.20+
HIGH 8.8
CVE-2026-2065
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu…
Smart Pixelator Firmware
No fix yet
HIGH 7.5
CVE-2026-25751
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, …
Fuxa
1.2.10+
CRITICAL 9.8
CVE-2026-25505
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign…
Bambuddy
0.1.7+
CRITICAL 10.0
CVE-2026-1633
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent…
Mitigation only
CRITICAL 9.1
CVE-2026-1632
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen…
Mitigation only
CRITICAL 9.3
CVE-2026-1341
Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
Mitigation only
CRITICAL 9.1
CVE-2026-25137EPSS 10%
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the …
Patch available
MEDIUM 6.5
CVE-2022-50980
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.
Mitigation only
CRITICAL 9.8
CVE-2022-50981
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is …
Mitigation only
HIGH 7.5
CVE-2022-50977
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.
Mitigation only
HIGH 7.5
CVE-2022-50978
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).
Mitigation only