Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-57206
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…
No fix yet
MEDIUM 6.5
CVE-2026-55440
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/serve…
Patch available
MEDIUM 5.3
CVE-2026-15106
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t…
No fix yet
MEDIUM 6.5
CVE-2026-53447
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoard…
Patch available
MEDIUM 6.5
CVE-2026-52892
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.chec…
Patch available
HIGH 7.6
CVE-2026-53444
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/…
Patch available
HIGH 7.1
CVE-2026-53445
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board b…
Patch available
CRITICAL 9.9
CVE-2026-54052
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with…
N8n Mcp
2.56.1+
MEDIUM 5.3
CVE-2026-33684
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in sign…
Mitigation only
HIGH 8.9
CVE-2026-56742
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users wi…
Cilium
1.17.17 / 1.18.11+
HIGH 7.6
CVE-2026-52870
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers in…
Mcp Python Sdk
1.27.2+
MEDIUM 5.4
CVE-2026-62348
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-priv…
Mitigation only
HIGH 7.1
CVE-2026-59255
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any a…
Patch available
HIGH 7.7
CVE-2026-53514
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtain…
Better Auth
1.6.11+
MEDIUM 6.5
CVE-2025-32781
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does…
Patch available
MEDIUM 5.3
CVE-2026-46459
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote atta…
Mitigation only
MEDIUM 6.5
CVE-2026-61440
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared …
Patch available
HIGH 7.7
CVE-2026-14251
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objec…
Mitigation only
HIGH 7.3
CVE-2026-15752
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the fil…
Patch available
CRITICAL 9.8
CVE-2026-53633
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarde…
Patch available
HIGH 8.8
CVE-2026-55052
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
MEDIUM 6.5
CVE-2026-58279
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Azure Cyclecloud
8.9.1+
MEDIUM 5.3
CVE-2026-60118
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden …
Patch available
MEDIUM 5.4
CVE-2026-60119
Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to …
Patch available
HIGH 8.2
CVE-2026-14504
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda …
Mitigation only
MEDIUM 6.4
CVE-2026-12988
The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the use…
Mitigation only
MEDIUM 5.3
CVE-2026-11802
The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5…
Mitigation only
HIGH 7.5
CVE-2026-62328
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user …
Mitigation only
HIGH 7.1
CVE-2026-62191
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers…
Openclaw
2026.6.9+
HIGH 8.8
CVE-2026-62194
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t…
Openclaw
2026.6.9+