Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-30825
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authentica…
Hoppscotch
2026.2.1+
HIGH 7.5
CVE-2026-30230
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint d…
Flare
1.7.2+
MEDIUM 5.3
CVE-2026-30231
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file …
Flare
1.7.2+
MEDIUM 6.5
CVE-2026-30843
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which cou…
Wekan
Patch available
MEDIUM 6.5
CVE-2026-25877
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…
Chartbrew
4.8.1+
HIGH 7.5
CVE-2026-28469
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy co…
Openclaw
2026.2.14+
MEDIUM 5.4
CVE-2026-27898
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated r…
Vaultwarden
1.35.4+
MEDIUM 5.3
CVE-2026-29069
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauth…
Craft Cms
4.17.0 / 5.9.0+
HIGH 7.5
CVE-2026-28696
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal ref…
Craft Cms
4.17.0 / 5.9.0+
MEDIUM 6.5
CVE-2026-28781
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the aut…
Craft Cms
4.17.0 / 5.9.0+
HIGH 8.4
CVE-2026-0020
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions …
Android
Mitigation only
MEDIUM 6.3
CVE-2026-28361
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing…
Nocodb
0.301.3+
HIGH 7.5
CVE-2025-58402
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter i…
Clininet
2025.ms4+
MEDIUM 6.5
CVE-2026-28354
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,…
Clipbucket
5.5.3-59+
MEDIUM 6.5
CVE-2026-27793
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint…
Seerr
3.1.0+
HIGH 7.1
CVE-2026-25147
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_pa…
Openemr
8.0.0+
MEDIUM 5.3
CVE-2026-1558
The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This i…
Mitigation only
HIGH 8.3
CVE-2026-28216
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's perso…
Hoppscotch
2026.2.0+
MEDIUM 6.5
CVE-2026-28217
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…
Hoppscotch
2026.2.0+
MEDIUM 6.5
CVE-2026-28225
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version…
Manyfold
0.133.1+
HIGH 7.5
CVE-2026-27449
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c…
Mitigation only
HIGH 7.5
CVE-2026-26265
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en…
Discourse
2025.12.0 / 2026.1.1+
HIGH 7.5
CVE-2026-26078
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting …
Discourse
2025.12.0 / 2026.1.1+
MEDIUM 6.5
CVE-2026-27943
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the e…
Openemr
after 8.0.0
MEDIUM 6.5
CVE-2026-25930
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based For…
Openemr
8.0.0+
HIGH 7.1
CVE-2026-25927
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer st…
Openemr
8.0.0+
MEDIUM 6.5
CVE-2026-25929
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document control…
Openemr
8.0.0+
MEDIUM 6.5
CVE-2026-25220
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center a…
Openemr
8.0.0+
MEDIUM 6.5
CVE-2026-27705
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/as…
Plane
1.2.2+
MEDIUM 5.3
CVE-2026-3185
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the…
Sz Boot Parent
after 0.9.0