Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-66589
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue aff…
Fix unknown
HIGH 8.7
CVE-2026-53453
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intende…
Fix unknown
MEDIUM 6.5
CVE-2026-12631
The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_…
Fix unknown
HIGH 7.7
CVE-2026-71307
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibl…
Fix unknown
HIGH 8.1
CVE-2026-71308
Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide…
Fix unknown
MEDIUM 6.5
CVE-2026-71317
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent aut…
Fix unknown
MEDIUM 6.9
CVE-2026-67440
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERF…
Fix unknown
CRITICAL 9.2
CVE-2026-67443
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integ…
Fix unknown
MEDIUM 6.3
CVE-2026-47721
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api…
Fix unknown
MEDIUM 5.3
CVE-2026-65959
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoin…
Fix unknown
HIGH 8.1
CVE-2026-67262
Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro…
Fix unknown
MEDIUM 5.3
CVE-2026-55106
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object…
Fix unknown
MEDIUM 5.4
CVE-2026-74004
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
Fix unknown
HIGH 7.5
CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
Fix unknown
MEDIUM 6.5
CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Fix unknown
HIGH 7.5
CVE-2026-73377
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Fix unknown
MEDIUM 6.5
CVE-2026-73348
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Fix unknown
MEDIUM 6.5
CVE-2026-73352
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Fix unknown
HIGH 8.2
CVE-2026-73356
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Fix unknown
HIGH 7.6
CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…
Fix unknown
MEDIUM 6.5
CVE-2026-66651
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Fix unknown
HIGH 7.5
CVE-2026-32549
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Fix unknown
HIGH 7.5
CVE-2026-32472
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
Fix unknown
HIGH 7.5
CVE-2026-28567
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Fix unknown
HIGH 7.5
CVE-2026-28571
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Fix unknown
HIGH 7.1
CVE-2026-75846
ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunct…
Fix unknown
HIGH 8.8
CVE-2026-75853
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no au…
Fix unknown
HIGH 8.8
CVE-2026-75836
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M…
Fix unknown
HIGH 7.5
CVE-2026-74904
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…
Fix unknown
HIGH 7.5
CVE-2026-11801
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…
Fix unknown