Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-43934
e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized …
Patch available
MEDIUM 5.3
CVE-2026-40127
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated use…
Mitigation only
HIGH 8.8
CVE-2026-35430
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ov…
Azure Privileged Identity Management
Mitigation only
HIGH 7.1
CVE-2026-39968
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …
Patch available
MEDIUM 6.5
CVE-2026-28444
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId …
Patch available
HIGH 7.1
CVE-2026-3473
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, whi…
Mattermost Server
10.11.15 / 11.4.5+
HIGH 7.5
CVE-2026-8679
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the h…
Patch available
MEDIUM 5.3
CVE-2026-8337
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public an…
Concrete Cms
9.5.1+
MEDIUM 5.3
CVE-2026-8204
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosu…
Concrete Cms
9.5.1+
HIGH 8.8
CVE-2026-47101
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generat…
Litellm
1.83.14+
HIGH 7.5
CVE-2025-13479
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Truste…
Mitigation only
HIGH 8.1
CVE-2026-45760
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K…
Mitigation only
CRITICAL 10.0
CVE-2026-9152
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri…
Mitigation only
MEDIUM 6.5
CVE-2026-9136
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request dat…
Misp
2.5.38+
HIGH 8.1
CVE-2026-9087
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId,
idpAlias) and is not bound to the upstream identit…
Build Of Keycloak
Mitigation only
MEDIUM 6.5
CVE-2026-6072
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all vers…
Mitigation only
HIGH 8.8
CVE-2026-42097
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only …
Pro Cloud Server
after 6.1.167
MEDIUM 6.8
CVE-2026-4630
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser…
Build Of Keycloak
26.4.12+
MEDIUM 6.9
CVE-2026-46721
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignm…
Mitigation only
MEDIUM 5.3
CVE-2026-33052
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add…
Patch available
HIGH 7.5
CVE-2026-41949
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up …
Dify
after 1.14.1
CRITICAL 9.1
CVE-2026-41947EPSS 6%
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…
Dify
after 1.14.1
MEDIUM 6.3
CVE-2026-8786
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i…
Weknora
after 0.3.6
MEDIUM 6.5
CVE-2026-45666
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} e…
Open Webui
0.8.11+
HIGH 8.3
CVE-2026-44570
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surroundin…
Open Webui
0.6.19+
HIGH 8.1
CVE-2026-45402
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-s…
Open Webui
0.9.5+
HIGH 7.5
CVE-2026-45398
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() chec…
Open Webui
0.9.5+
HIGH 8.0
CVE-2026-45671
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permane…
Open Webui
0.9.0+
HIGH 7.1
CVE-2026-45349
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API e…
Open Webui
0.9.0+
HIGH 8.1
CVE-2026-46407
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-toke…
Mitigation only