Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-12998
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…
No fix yet
MEDIUM 6.5
CVE-2026-13358
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference…
No fix yet
CRITICAL 9.8
CVE-2026-16142
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_…
No fix yet
MEDIUM 5.3
CVE-2026-74242
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U…
No fix yet
HIGH 8.6
CVE-2026-19870
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding …
No fix yet
HIGH 8.8
CVE-2026-73841
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an…
No fix yet
MEDIUM 5.4
CVE-2026-73039
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete othe…
No fix yet
CRITICAL 9.9
CVE-2026-73656
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…
No fix yet
MEDIUM 6.5
CVE-2026-72680
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on…
No fix yet
MEDIUM 6.8
CVE-2026-72666
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigne…
No fix yet
MEDIUM 6.5
CVE-2026-72657
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variab…
No fix yet
HIGH 7.1
CVE-2026-72629
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Prop…
No fix yet
CRITICAL 9.6
CVE-2026-73644
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org…
No fix yet
HIGH 8.1
CVE-2026-72741
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth…
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
MEDIUM 5.4
CVE-2026-58435
Gitea LFS Deploy-Key Privilege Escalation
No fix yet
MEDIUM 5.9
CVE-2026-57886
Cross-repository issue/comment attachment re-linking can expose private attachment content
No fix yet
HIGH 8.6
CVE-2026-19734
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4…
No fix yet
MEDIUM 6.5
CVE-2026-28155
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73616
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to ot…
No fix yet
MEDIUM 5.8
CVE-2026-73606
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-prote…
No fix yet
MEDIUM 5.8
CVE-2026-73610
SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map…
No fix yet
HIGH 8.1
CVE-2026-73612
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authentica…
No fix yet
MEDIUM 6.0
CVE-2026-73488
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo…
No fix yet
HIGH 8.2
CVE-2026-18945
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling …
No fix yet
MEDIUM 5.3
CVE-2026-18750
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the …
No fix yet
MEDIUM 6.5
CVE-2026-18744
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func on…
No fix yet
CRITICAL 9.8
CVE-2026-18749
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac…
No fix yet
MEDIUM 5.8
CVE-2026-19130
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust…
No fix yet
HIGH 8.2
CVE-2026-73303
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId with…
No fix yet