Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-57660
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
Mitigation only
MEDIUM 5.4
CVE-2026-57661
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57654
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Mitigation only
HIGH 8.1
CVE-2026-57645
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
Mitigation only
MEDIUM 5.4
CVE-2026-57632
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57324
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
No fix yet
MEDIUM 5.8
CVE-2026-57323
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
No fix yet
HIGH 8.8
CVE-2026-56773
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attack…
Patch available
HIGH 7.5
CVE-2026-56061
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
Mitigation only
HIGH 8.3
CVE-2026-56063
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
Mitigation only
HIGH 8.8
CVE-2026-56038
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
No fix yet
HIGH 7.5
CVE-2026-56025
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
Mitigation only
HIGH 7.5
CVE-2026-54835
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
Mitigation only
HIGH 7.5
CVE-2026-54837
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
Mitigation only
HIGH 7.3
CVE-2026-54840
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
Mitigation only
HIGH 7.5
CVE-2026-54846
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
Mitigation only
HIGH 7.5
CVE-2026-54847
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
Mitigation only
HIGH 7.5
CVE-2026-54832
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-52701
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
No fix yet
MEDIUM 5.3
CVE-2026-24547
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
Mitigation only
MEDIUM 5.3
CVE-2025-64636
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
Mitigation only
MEDIUM 5.4
CVE-2025-63041
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
Mitigation only
HIGH 7.5
CVE-2026-57923
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
Youtrack
2026.2.16593+
MEDIUM 5.3
CVE-2026-57925
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Youtrack
2026.2.16593+
HIGH 7.5
CVE-2026-57921
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
Youtrack
2026.2.16593+
MEDIUM 5.3
CVE-2026-57922
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Youtrack
2026.2.16593+
MEDIUM 6.5
CVE-2026-1869
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buil…
Mitigation only
HIGH 7.1
CVE-2026-57520
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to …
Server
2026.5.0+
HIGH 8.8
CVE-2026-56767
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authentica…
Patch available
HIGH 8.8
CVE-2026-56768
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass auth…
Patch available