Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-65523
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
No fix yet
MEDIUM 5.3
CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-14313
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco…
No fix yet
HIGH 7.1
CVE-2026-9130
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access …
Langflow
1.11.0+
MEDIUM 6.5
CVE-2026-48912
Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar…
Answer
2.0.2+
MEDIUM 6.5
CVE-2026-71251
Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth mid…
No fix yet
HIGH 8.3
CVE-2026-71242
Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol…
No fix yet
HIGH 8.3
CVE-2026-55739
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->compan…
No fix yet
MEDIUM 6.5
CVE-2026-11454
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up…
No fix yet
MEDIUM 5.3
CVE-2026-16981
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or owne…
No fix yet
MEDIUM 6.3
CVE-2026-18818
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views…
No fix yet
HIGH 8.3
CVE-2026-70476
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa…
No fix yet
HIGH 8.8
CVE-2026-69258
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/…
No fix yet
HIGH 8.5
CVE-2026-69250
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/…
No fix yet
MEDIUM 6.3
CVE-2026-18722
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey…
No fix yet
MEDIUM 6.3
CVE-2026-18631
A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr…
No fix yet
CRITICAL 9.8
CVE-2026-2346
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affe…
No fix yet
MEDIUM 6.5
CVE-2026-68582
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1…
No fix yet
HIGH 7.1
CVE-2025-71400
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth…
No fix yet
CRITICAL 9.8
CVE-2026-67342
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…
No fix yet
HIGH 7.1
CVE-2026-67329
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscri…
No fix yet
HIGH 8.3
CVE-2026-67331
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authentic…
No fix yet
MEDIUM 5.3
CVE-2025-14073
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in …
No fix yet
HIGH 7.1
CVE-2026-65981
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH reque…
No fix yet
CRITICAL 9.6
CVE-2026-17349
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…
Pgadmin 4
9.17+
MEDIUM 5.3
CVE-2026-17567
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…
No fix yet
MEDIUM 5.4
CVE-2026-8155
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated …
No fix yet
MEDIUM 6.5
CVE-2026-15209
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated…
No fix yet
MEDIUM 5.3
CVE-2026-14843
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un…
No fix yet
MEDIUM 5.4
CVE-2026-12697
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag…
No fix yet