Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-33158
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …
Craft Cms
4.17.8 / 5.9.14+
HIGH 8.1
CVE-2026-33678
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`W…
Vikunja
2.2.1+
HIGH 7.5
CVE-2026-33484EPSS 6%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…
Langflow
1.9.0+
HIGH 8.1
CVE-2026-32300
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…
Connect Cms
1.41.1 / 2.41.1+
MEDIUM 6.5
CVE-2026-23487
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…
Blinko
1.8.4+
MEDIUM 5.3
CVE-2026-23488
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…
Blinko
1.8.4+
MEDIUM 6.5
CVE-2026-30886
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure…
New Api
0.11.4+
CRITICAL 9.1
CVE-2026-33297
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr…
Avideo
26.0+
MEDIUM 5.3
CVE-2026-33425
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe…
Discourse
2026.1.2 / 2026.2.1+
HIGH 8.8
CVE-2026-33053
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accept…
Langflow
1.9.0+
MEDIUM 6.5
CVE-2026-32761
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…
Filebrowser
2.62.0+
HIGH 8.1
CVE-2026-29189
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the Sui…
Suitecrm
7.15.1 / 8.9.3+
MEDIUM 6.5
CVE-2026-32697
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler…
Suitecrm
8.9.3+
MEDIUM 6.5
CVE-2026-32039
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t…
Openclaw
2026.2.22+
MEDIUM 6.5
CVE-2026-33304
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in…
Openemr
8.0.0.2+
MEDIUM 6.5
CVE-2026-25744
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API a…
Openemr
8.0.0.2+
CRITICAL 9.8
CVE-2026-32867
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…
Ecase Ecomplaint
10.1.0.0+
MEDIUM 6.5
CVE-2025-32223
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Sec…
Mitigation only
MEDIUM 6.5
CVE-2026-27397
Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly…
Mitigation only
MEDIUM 6.5
CVE-2026-25745
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the m…
Openemr
after 8.0.0
MEDIUM 6.6
CVE-2026-32694
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a …
Juju
3.6.19+
CRITICAL 9.6
CVE-2026-30884
mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P…
Patch available
MEDIUM 6.5
CVE-2026-26004
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object…
Sentry
26.1.0+
HIGH 8.8
CVE-2026-24901
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the doc…
Outline
1.4.0+
HIGH 8.8
CVE-2026-4208
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login at…
Mfa Mail
1.0.7+
MEDIUM 5.3
CVE-2025-69727
An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPho…
Mitigation only
MEDIUM 6.3
CVE-2026-4171
A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of t…
Mitigation only
HIGH 8.6
CVE-2026-3020
Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing th…
Mitigation only
HIGH 7.5
CVE-2026-1947
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and…
Mitigation only
CRITICAL 9.8
CVE-2017-20223
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…
Sdt Cs3b1 Firmware
Mitigation only