Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-16774
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handle…
No fix yet
MEDIUM 5.3
CVE-2026-13110
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a mis…
No fix yet
HIGH 7.5
CVE-2026-15025
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in vers…
No fix yet
MEDIUM 5.3
CVE-2026-15411
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to au…
No fix yet
HIGH 8.8
CVE-2026-14168
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulti…
Mitigation only
HIGH 7.5
CVE-2026-14924
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allo…
No fix yet
MEDIUM 5.3
CVE-2026-12124
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauth…
No fix yet
MEDIUM 6.5
CVE-2026-65445
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
No fix yet
HIGH 7.5
CVE-2026-66473
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-64746
An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS…
Ipados
26.6+
MEDIUM 5.5
CVE-2026-43665
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may b…
macOS
14.8.8 / 15.7.8+
MEDIUM 5.4
CVE-2026-65922
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted in…
Artifactory
7.111.18 / 7.117.25+
MEDIUM 5.3
CVE-2026-66477
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
No fix yet
MEDIUM 5.4
CVE-2026-66442
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
No fix yet
MEDIUM 5.0
CVE-2026-65568
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-65567
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65433
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65435
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
No fix yet
MEDIUM 6.5
CVE-2026-59560
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
No fix yet
MEDIUM 6.5
CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
No fix yet
HIGH 7.3
CVE-2026-59535
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
No fix yet
HIGH 7.5
CVE-2026-59536
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
No fix yet
HIGH 7.5
CVE-2026-59529
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
No fix yet
HIGH 7.5
CVE-2026-59530
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
No fix yet
HIGH 7.5
CVE-2026-59534
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
No fix yet
HIGH 8.0
CVE-2026-59690
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi…
Connection Manager For Objectscale
7.1.35.16 / 7.2.54.19+
MEDIUM 5.3
CVE-2026-13390
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes an…
No fix yet
CRITICAL 10.0
CVE-2026-66012
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mo…
No fix yet
HIGH 8.3
CVE-2026-66027
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipul…
No fix yet
MEDIUM 6.5
CVE-2026-49326
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan operation in thrift/rest service has 3 steps, open, f…
Hbase
2.5.15 / 2.6.6+