Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-70481
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an…
No fix yet
HIGH 7.1
CVE-2026-70475
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in p…
No fix yet
HIGH 8.3
CVE-2026-70473
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-histor…
No fix yet
HIGH 7.1
CVE-2026-13229
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
No fix yet
HIGH 7.2
CVE-2026-69252
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only b…
No fix yet
HIGH 8.8
CVE-2026-18650
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.
No fix yet
HIGH 8.8
CVE-2026-17070
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects L…
No fix yet
HIGH 8.2
CVE-2026-58080
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe…
Milo
1.1.5+
MEDIUM 6.5
CVE-2026-63248
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia…
Milo
1.1.5+
CRITICAL 9.3
CVE-2026-15958
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions …
No fix yet
HIGH 8.8
CVE-2026-66326
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
151.0.4129.59+
MEDIUM 6.2
CVE-2026-66311
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
Edge Chromium
151.0.4129.59+
CRITICAL 9.8
CVE-2026-68979
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…
Nifi
2.11.0+
MEDIUM 5.8
CVE-2026-68585
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata…
No fix yet
HIGH 8.6
CVE-2026-68586
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and…
No fix yet
HIGH 8.6
CVE-2026-68587
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get…
No fix yet
MEDIUM 5.4
CVE-2026-28147
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorr…
No fix yet
CRITICAL 9.8
CVE-2026-16300
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass…
No fix yet
CRITICAL 9.4
CVE-2026-15930
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value …
No fix yet
MEDIUM 6.5
CVE-2026-16057
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gati…
No fix yet
HIGH 7.8
CVE-2026-20495
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with U…
No fix yet
HIGH 7.7
CVE-2026-20483
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…
No fix yet
HIGH 7.2
CVE-2026-18571
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18573
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-18570
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…
Build Of Keycloak
No fix yet
HIGH 7.5
CVE-2026-16285
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a…
No fix yet
MEDIUM 5.5
CVE-2026-15248
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing …
No fix yet
MEDIUM 6.5
CVE-2026-13389
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen…
No fix yet
MEDIUM 6.5
CVE-2026-17580
The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin f…
No fix yet
MEDIUM 5.3
CVE-2026-11995
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorizatio…
No fix yet