Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-12406
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authori…
Mitigation only
MEDIUM 6.5
CVE-2026-48492
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorizati…
Snipe It
8.6.0+
CRITICAL 9.8
CVE-2026-31309
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to…
Patch available
HIGH 8.1
CVE-2026-35552
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administ…
Mitigation only
MEDIUM 5.3
CVE-2026-7492
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under …
GitLab
18.11.7 / 19.0.4+
MEDIUM 6.5
CVE-2026-59805
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate…
Patch available
HIGH 7.7
CVE-2026-14373
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This …
Mitigation only
MEDIUM 6.5
CVE-2026-59262
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace member…
Patch available
MEDIUM 5.3
CVE-2026-60124
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persis…
Patch available
HIGH 7.5
CVE-2026-56250
Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbit…
Mitigation only
HIGH 7.5
CVE-2026-5356
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions u…
Mitigation only
MEDIUM 5.3
CVE-2026-12097
The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin n…
Mitigation only
CRITICAL 9.8
CVE-2026-12153
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi…
Mitigation only
MEDIUM 5.4
CVE-2026-55432
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `Cre…
Coder
2.29.17 / 2.32.7+
MEDIUM 5.4
CVE-2026-55433
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devc…
Coder
2.29.17 / 2.32.7+
HIGH 7.1
CVE-2026-59704
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summarie…
Patch available
CRITICAL 9.1
CVE-2026-58473
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf…
Patch available
MEDIUM 6.9
CVE-2026-55417
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile opti…
Mitigation only
HIGH 8.7
CVE-2026-53730
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @D…
Patch available
HIGH 7.2
CVE-2026-50007
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budg…
Patch available
HIGH 7.5
CVE-2026-59708
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing una…
Patch available
HIGH 8.3
CVE-2026-11340
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects L…
Mitigation only
HIGH 8.2
CVE-2026-8377
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource …
Mitigation only
CRITICAL 9.9
CVE-2026-34048
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots…
Patch available
MEDIUM 6.9
CVE-2026-53647
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp…
Mitigation only
HIGH 8.7
CVE-2026-53643
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut…
Mitigation only
MEDIUM 6.5
CVE-2026-34050
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Liv…
Patch available
HIGH 7.8
CVE-2026-6509
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation.
This issue…
Mitigation only
HIGH 8.2
CVE-2026-27771EPSS 43%
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal…
Patch available
HIGH 7.5
CVE-2026-25038
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Patch available