Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-25440
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
Mitigation only
MEDIUM 6.3
CVE-2025-68049
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
Mitigation only
MEDIUM 6.5
CVE-2025-69332
Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-38329
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.p…
Mitigation only
HIGH 7.1
CVE-2026-5230
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Con…
Mitigation only
MEDIUM 6.5
CVE-2026-48969
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
Mitigation only
MEDIUM 6.5
CVE-2025-64215
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs.
This issu…
Mitigation only
HIGH 8.6
CVE-2026-34024
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. A…
Mitigation only
MEDIUM 6.6
CVE-2026-53820
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated call…
Openclaw
2026.5.12+
HIGH 8.8
CVE-2026-53821
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization …
Openclaw
2026.5.18+
HIGH 7.1
CVE-2026-47120
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…
Mitigation only
HIGH 7.1
CVE-2026-48119
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authent…
Mitigation only
CRITICAL 9.9
CVE-2026-46716
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…
Mitigation only
MEDIUM 5.3
CVE-2026-45085
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…
Discourse
2026.1.0 / 2026.1.4+
HIGH 7.8
CVE-2026-42851
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a d…
Kitty
0.47.0+
HIGH 7.5
CVE-2026-50108
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the l…
Mitigation only
MEDIUM 5.3
CVE-2026-50244
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account …
Mitigation only
MEDIUM 5.1
CVE-2026-10715
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user…
Patch available
MEDIUM 6.9
CVE-2026-50026
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unau…
Mitigation only
MEDIUM 6.5
CVE-2026-50084
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an inst…
Cloud Production Api
No fix yet
MEDIUM 5.3
CVE-2026-44975
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users i…
Mitigation only
HIGH 8.1
CVE-2026-7368
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credent…
Mitigation only
HIGH 7.2
CVE-2026-47197
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate user…
Mitigation only
MEDIUM 6.6
CVE-2026-53818
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only…
Openclaw
2026.4.24+
MEDIUM 6.5
CVE-2026-53815
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal…
Openclaw
2026.5.19+
HIGH 7.2
CVE-2026-53816
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec …
Openclaw
2026.5.18+
HIGH 7.2
CVE-2026-47163
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke sl…
Mitigation only
CRITICAL 9.4
CVE-2026-4764
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit…
Mitigation only
MEDIUM 5.4
CVE-2023-25969
Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control S…
Mitigation only
MEDIUM 5.4
CVE-2022-45813
Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels…
Mitigation only