Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2026-71417
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using …
Fix unknown
HIGH 8.1
CVE-2026-71308
Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide…
Fix unknown
CRITICAL 9.9
CVE-2026-55166
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si…
Fix unknown
MEDIUM 6.5
CVE-2026-69160
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st…
Fix unknown
MEDIUM 5.3
CVE-2026-50167
Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi…
Fix unknown
HIGH 8.8
CVE-2026-61574
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo…
Fix unknown
HIGH 8.3
CVE-2026-49225
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revis…
Fix unknown
HIGH 8.8
CVE-2026-49228
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product opera…
Fix unknown
HIGH 7.6
CVE-2026-19869
@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le…
Fix unknown
HIGH 7.6
CVE-2026-49222
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product quest…
Fix unknown
HIGH 7.6
CVE-2026-49223
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revie…
Fix unknown
HIGH 8.3
CVE-2026-49224
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision…
Fix unknown
HIGH 8.8
CVE-2026-49221
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset…
Fix unknown
HIGH 8.3
CVE-2026-49226
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio…
Fix unknown
HIGH 7.6
CVE-2026-49227
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera…
Fix unknown
MEDIUM 5.4
CVE-2026-45120
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w…
Fix unknown
MEDIUM 5.3
CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
Fix unknown
MEDIUM 6.5
CVE-2026-73395
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
Fix unknown
MEDIUM 6.5
CVE-2026-73189
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
Fix unknown
HIGH 7.6
CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…
Fix unknown
MEDIUM 5.3
CVE-2026-16309
Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly…
Fix unknown
MEDIUM 6.5
CVE-2026-63178
Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/u…
Fix unknown
HIGH 8.8
CVE-2026-75103
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's…
Fix unknown
HIGH 7.5
CVE-2026-75105
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/ind…
Fix unknown
MEDIUM 6.5
CVE-2026-63669
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destinati…
Fix unknown
HIGH 8.8
CVE-2026-74877
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clien…
Fix unknown
MEDIUM 6.3
CVE-2026-19994
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-…
Fix unknown
MEDIUM 5.3
CVE-2026-14832
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup e…
Fix unknown
HIGH 8.3
CVE-2026-19979
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M…
Fix unknown
MEDIUM 5.4
CVE-2026-19966
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/…
Fix unknown