Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-69114
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers t…
No fix yet
CRITICAL 9.9
CVE-2026-72863
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…
No fix yet
MEDIUM 5.3
CVE-2026-68870
The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-ag…
No fix yet
MEDIUM 6.5
CVE-2026-68871
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…
Apache Airflow Providers Apache Yandex
No fix yet
MEDIUM 6.5
CVE-2026-68872
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…
Apache Airflow Providers Amazon
No fix yet
CRITICAL 9.6
CVE-2026-72737
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …
No fix yet
HIGH 8.4
CVE-2026-72734
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/…
No fix yet
HIGH 8.6
CVE-2026-19433
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated us…
No fix yet
HIGH 7.5
CVE-2026-72689
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read com…
No fix yet
HIGH 7.1
CVE-2026-72690
An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory su…
No fix yet
HIGH 8.7
CVE-2026-59233
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role…
No fix yet
CRITICAL 9.6
CVE-2026-72564
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in …
No fix yet
MEDIUM 6.5
CVE-2026-19077
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing an…
No fix yet
MEDIUM 5.4
CVE-2026-15238
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticat…
No fix yet
MEDIUM 5.4
CVE-2026-16574
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belong…
No fix yet
HIGH 8.8
CVE-2026-48169
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…
No fix yet
MEDIUM 6.5
CVE-2026-70561
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege gues…
No fix yet
MEDIUM 5.3
CVE-2026-66058
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss…
No fix yet
MEDIUM 6.5
CVE-2026-16039
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated us…
No fix yet
MEDIUM 6.5
CVE-2026-70557
diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those …
No fix yet
CRITICAL 9.9
CVE-2026-67622
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac…
No fix yet
MEDIUM 6.5
CVE-2026-64662
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con…
No fix yet
HIGH 8.5
CVE-2026-45414
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th…
No fix yet
HIGH 8.1
CVE-2026-19111
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might…
No fix yet
MEDIUM 5.3
CVE-2026-14842
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauth…
No fix yet
MEDIUM 5.3
CVE-2026-15147
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to v…
No fix yet
HIGH 7.5
CVE-2026-13399
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau…
No fix yet
HIGH 7.5
CVE-2026-10599
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order bein…
No fix yet
HIGH 8.8
CVE-2026-18258
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows …
Escriptorium
No fix yet
MEDIUM 6.5
CVE-2026-18275
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to…
Escriptorium
No fix yet