Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-72802
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths…
No fix yet
HIGH 8.5
CVE-2026-19228
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could…
No fix yet
HIGH 8.7
CVE-2026-73298
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for m…
No fix yet
MEDIUM 6.5
CVE-2026-73239
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
This issue affects Apache All…
Allura
No fix yet
MEDIUM 5.4
CVE-2026-68076
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-47230
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same ro…
No fix yet
HIGH 8.1
CVE-2026-47231
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking tha…
No fix yet
MEDIUM 6.5
CVE-2026-47227
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, ……
No fix yet
MEDIUM 6.5
CVE-2026-47226
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can…
No fix yet
MEDIUM 5.3
CVE-2026-16737
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identif…
No fix yet
MEDIUM 6.4
CVE-2026-64927
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the syst…
No fix yet
HIGH 7.7
CVE-2026-66878
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subs…
No fix yet
CRITICAL 9.9
CVE-2026-48765
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from…
No fix yet
MEDIUM 5.4
CVE-2026-19579
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The ca…
No fix yet
MEDIUM 6.5
CVE-2026-69117
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitr…
No fix yet
HIGH 8.3
CVE-2026-69119
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or pe…
No fix yet
HIGH 7.1
CVE-2026-48494
TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook …
No fix yet
HIGH 7.8
CVE-2026-58650
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
No fix yet
HIGH 7.1
CVE-2026-47704
TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook ses…
No fix yet
MEDIUM 5.9
CVE-2026-73068
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, th…
No fix yet
HIGH 8.8
CVE-2026-56721
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authentic…
No fix yet
HIGH 7.1
CVE-2026-72774
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access…
No fix yet
HIGH 7.2
CVE-2026-72763
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside…
No fix yet
HIGH 7.1
CVE-2026-72546
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees an…
No fix yet
HIGH 7.1
CVE-2026-72547
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attende…
No fix yet
HIGH 7.5
CVE-2026-72543
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any con…
No fix yet
HIGH 7.5
CVE-2026-72545
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any con…
No fix yet
HIGH 7.5
CVE-2026-19424
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp…
No fix yet
HIGH 7.1
CVE-2026-18620
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServic…
No fix yet
CRITICAL 9.9
CVE-2026-72876
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA…
No fix yet