Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2026-73658
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…
No fix yet
HIGH 8.8
CVE-2026-73305
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…
No fix yet
CRITICAL 9.9
CVE-2026-73656
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…
No fix yet
HIGH 7.1
CVE-2026-72675
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPE…
No fix yet
MEDIUM 6.5
CVE-2026-72681
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates …
No fix yet
HIGH 8.1
CVE-2026-72665
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Acce…
No fix yet
HIGH 7.6
CVE-2026-72669
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update …
No fix yet
MEDIUM 6.5
CVE-2026-72661
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). …
No fix yet
MEDIUM 6.5
CVE-2026-72664
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functi…
No fix yet
HIGH 7.1
CVE-2026-59714
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite …
No fix yet
CRITICAL 9.4
CVE-2026-73653
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
CRITICAL 9.1
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
No fix yet
HIGH 7.5
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
No fix yet
HIGH 7.5
CVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
No fix yet
MEDIUM 5.9
CVE-2026-57886
Cross-repository issue/comment attachment re-linking can expose private attachment content
No fix yet
MEDIUM 5.3
CVE-2026-73349
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73353
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73401
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
No fix yet
MEDIUM 5.3
CVE-2026-73403
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
No fix yet
MEDIUM 6.3
CVE-2026-66689
Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66693
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66660
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
No fix yet
HIGH 7.5
CVE-2026-66469
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
No fix yet
HIGH 7.5
CVE-2026-66461
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66464
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
No fix yet
HIGH 7.5
CVE-2026-66466
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= …
No fix yet
MEDIUM 6.5
CVE-2026-66454
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
No fix yet
MEDIUM 6.0
CVE-2026-66455
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66459
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
No fix yet