Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.7
CVE-2026-47743
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da…
No fix yet
MEDIUM 6.5
CVE-2026-47755
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth…
No fix yet
MEDIUM 5.4
CVE-2026-65696
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenti…
No fix yet
HIGH 8.8
CVE-2026-65917
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's …
No fix yet
MEDIUM 5.3
CVE-2026-65501
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
No fix yet
MEDIUM 5.4
CVE-2026-65463
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
No fix yet
MEDIUM 6.5
CVE-2026-61946
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
No fix yet
MEDIUM 5.3
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could…
Sterling B2b Integrator
after 6.2.2.0_1
CRITICAL 9.6
CVE-2026-16624
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated tea…
No fix yet
HIGH 8.8
CVE-2026-65013
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to acc…
No fix yet
HIGH 8.8
CVE-2026-65016
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provi…
N8n
1.123.64 / 2.29.8+
MEDIUM 6.5
CVE-2026-2406
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration an…
No fix yet
MEDIUM 6.5
CVE-2026-65316
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from j…
No fix yet
MEDIUM 5.4
CVE-2026-61064
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affec…
Irecruitment
after 12.2.15
HIGH 7.1
CVE-2026-56147
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity co…
Kibana
8.19.18 / 9.3.7+
HIGH 7.6
CVE-2026-47414
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
No fix yet
HIGH 8.3
CVE-2026-47415
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
No fix yet
HIGH 8.1
CVE-2026-47417
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
Mitigation only
HIGH 8.1
CVE-2026-47418
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
No fix yet
HIGH 8.3
CVE-2026-47419
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Referenc…
No fix yet
HIGH 8.1
CVE-2026-47406
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
No fix yet
CRITICAL 9.4
CVE-2026-47407
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un…
No fix yet
MEDIUM 6.5
CVE-2026-47408
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…
No fix yet
HIGH 8.8
CVE-2026-47399
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain…
Mitigation only
MEDIUM 6.5
CVE-2026-15342
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or…
No fix yet
CRITICAL 9.1
CVE-2026-28317
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …
Serv U
2026.3+
CRITICAL 9.1
CVE-2026-28313
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…
Serv U
2026.3+
CRITICAL 9.1
CVE-2026-28314
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required…
Serv U
2026.3+
CRITICAL 9.1
CVE-2026-28316
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr…
Serv U
2026.3+
CRITICAL 9.1
CVE-2026-28305
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain ac…
Serv U
2026.3+