Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-5326
A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_use…
Mitigation only
HIGH 8.1
CVE-2026-5246
A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co…
Mongoose
7.21+
MEDIUM 6.5
CVE-2026-32976
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration …
Openclaw
2026.3.11+
MEDIUM 6.5
CVE-2026-4400
Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by sim…
Millie Chatbot
3.6.0+
CRITICAL 9.9
CVE-2026-33030
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) …
Nginx Ui
after 2.3.3
HIGH 8.7
CVE-2026-3321
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting…
Mitigation only
HIGH 7.5
CVE-2026-3124
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the execu…
Mitigation only
MEDIUM 5.9
CVE-2026-33946
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transpor…
Mcp Ruby Sdk
0.9.2+
HIGH 8.8
CVE-2026-34046
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l…
Langflow Base
0.5.1 / 1.5.0+
MEDIUM 5.3
CVE-2026-31950
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:…
Librechat
No fix yet
MEDIUM 6.5
CVE-2026-4958
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentSe…
Xagent
No fix yet
MEDIUM 5.3
CVE-2026-33759
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full …
Avideo
after 26.0
CRITICAL 9.3
CVE-2026-1496
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an aut…
Mitigation only
MEDIUM 6.5
CVE-2026-33730
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2…
Open Source Point Of Sale
3.4.2+
HIGH 8.8
CVE-2026-33735
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/impor…
Mytube
1.8.69+
HIGH 7.1
CVE-2026-28788
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can…
Open Webui
0.8.6+
MEDIUM 6.5
CVE-2026-28503
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.que…
Recipes
2.6.0+
MEDIUM 6.3
CVE-2026-34055
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient…
Openemr
8.0.0.3+
MEDIUM 6.5
CVE-2026-33931
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct…
Openemr
8.0.0.3+
MEDIUM 6.3
CVE-2026-32120
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct…
Openemr
8.0.0.3+
HIGH 7.5
CVE-2025-14974
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).
Infosphere Information Server
after 11.7.1.6
HIGH 7.4
CVE-2026-33724
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command…
N8n
2.5.0+
MEDIUM 6.5
CVE-2026-33663
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` ro…
N8n
1.123.27 / 2.13.3+
MEDIUM 6.5
CVE-2026-32535
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Acc…
Mitigation only
MEDIUM 6.5
CVE-2026-32533
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Contr…
Mitigation only
CRITICAL 9.8
CVE-2026-2414
Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 befor…
Hypr
10.7.2+
HIGH 8.6
CVE-2025-69347
Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Ac…
Mitigation only
CRITICAL 9.8
CVE-2026-33511
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator i…
Pyload Ng
0.5.0b3.dev97+
MEDIUM 6.5
CVE-2026-33345
solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project…
Solidtime
0.11.6+
MEDIUM 5.3
CVE-2026-33160
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …
Craft Cms
4.17.8 / 5.9.14+