Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-68500
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_lo…
No fix yet
MEDIUM 6.5
CVE-2026-68501
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_loc…
No fix yet
MEDIUM 6.5
CVE-2026-10700
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access …
Langflow
1.9.0+
HIGH 7.1
CVE-2026-12945
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on …
Langflow
1.10.2+
HIGH 8.1
CVE-2026-15658
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that
returns the records of o…
No fix yet
HIGH 8.1
CVE-2026-67348
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot…
No fix yet
MEDIUM 5.3
CVE-2026-15255
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the ident…
No fix yet
MEDIUM 5.3
CVE-2026-15257
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing ac…
No fix yet
MEDIUM 5.4
CVE-2026-14310
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning o…
No fix yet
HIGH 7.5
CVE-2026-13178
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth…
No fix yet
MEDIUM 5.3
CVE-2026-13345
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom…
No fix yet
HIGH 7.5
CVE-2025-60931
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attacker…
No fix yet
MEDIUM 6.5
CVE-2026-5060
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…
No fix yet
MEDIUM 5.4
CVE-2026-14224
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the…
No fix yet
HIGH 8.8
CVE-2026-57510
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user…
No fix yet
HIGH 8.8
CVE-2026-49258
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper…
No fix yet
MEDIUM 6.9
CVE-2026-59240
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notifi…
No fix yet
MEDIUM 5.4
CVE-2026-48052
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organizatio…
No fix yet
MEDIUM 5.0
CVE-2026-17531
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route…
No fix yet
HIGH 7.5
CVE-2026-59539
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
No fix yet
HIGH 7.4
CVE-2026-59546
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
No fix yet
HIGH 7.7
CVE-2026-17527
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, include…
No fix yet
MEDIUM 6.5
CVE-2026-66412
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are…
No fix yet
CRITICAL 9.3
CVE-2026-66013
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to upd…
No fix yet
HIGH 8.1
CVE-2026-65708
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi…
No fix yet
HIGH 8.3
CVE-2026-65709
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume…
No fix yet
HIGH 7.1
CVE-2026-65710
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag…
No fix yet
MEDIUM 6.5
CVE-2026-17059
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…
Build Of Keycloak
No fix yet
MEDIUM 5.3
CVE-2026-13464
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
No fix yet
CRITICAL 9.9
CVE-2026-15630
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…
No fix yet