Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-54105
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D…
Mitigation only
HIGH 7.1
CVE-2026-50141
Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authen…
Patch available
HIGH 7.1
CVE-2026-48759
TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme Tem…
Mitigation only
HIGH 8.2
CVE-2026-50194
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management…
Patch available
MEDIUM 6.5
CVE-2026-55197
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose …
Patch available
MEDIUM 6.5
CVE-2026-55198
Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access …
Patch available
MEDIUM 5.3
CVE-2025-15657
Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
Mitigation only
HIGH 8.2
CVE-2026-54184
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Mitigation only
HIGH 7.3
CVE-2026-40768
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-53863
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca…
Openclaw
2026.4.25+
HIGH 7.6
CVE-2026-48599
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belon…
Patch available
HIGH 7.5
CVE-2026-52699
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
Mitigation only
HIGH 7.5
CVE-2026-48868
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
Mitigation only
HIGH 7.5
CVE-2026-48872
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Mitigation only
MEDIUM 6.3
CVE-2026-40792
Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-39518
Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
Mitigation only
HIGH 7.5
CVE-2025-59133
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
Mitigation only
HIGH 7.3
CVE-2026-12204
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveInteg…
Mitigation only
HIGH 8.8
CVE-2026-54361
MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Se…
Patch available
MEDIUM 5.1
CVE-2026-54357
An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to si…
Patch available
HIGH 8.4
CVE-2026-54360
A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a …
Patch available
MEDIUM 6.9
CVE-2026-53726
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a…
Patch available
HIGH 8.8
CVE-2026-42947
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbi…
Mitigation only
HIGH 8.8
CVE-2026-8828
A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, …
Mitigation only
HIGH 8.8
CVE-2026-45830
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, writ…
Chromadb
after 1.5.9
HIGH 8.8
CVE-2026-45832
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers t…
Chromadb
after 1.5.9
MEDIUM 6.9
CVE-2026-44207
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access …
Mitigation only
MEDIUM 6.5
CVE-2026-47238
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt…
Mitigation only
HIGH 8.3
CVE-2026-47189
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up a…
Mitigation only
HIGH 8.1
CVE-2026-7787
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using inse…
Langflow
1.9.2+