Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2022-42479
Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Sol…
Mitigation only
HIGH 7.2
CVE-2026-0272
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int…
Pan Os
10.2.7 / 10.2.10+
HIGH 7.7
CVE-2026-49821
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 7.7
CVE-2026-49822
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
CRITICAL 9.8
CVE-2026-46614
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 8.3
CVE-2026-46558
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…
Plane
1.3.1+
CRITICAL 9.1
CVE-2026-45550
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo…
Mitigation only
CRITICAL 9.9
CVE-2026-45552
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares …
Mitigation only
HIGH 8.5
CVE-2026-45549
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/a…
Mitigation only
MEDIUM 6.5
CVE-2026-11852
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifa…
Mitigation only
HIGH 7.5
CVE-2026-26237
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…
Qumagie
2.9.0+
HIGH 8.7
CVE-2026-46518
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-sit…
Openemr
8.0.0.1+
MEDIUM 6.5
CVE-2026-49956
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to ot…
Patch available
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
HIGH 8.1
CVE-2026-49948
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POS…
Patch available
MEDIUM 5.3
CVE-2026-47352
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to f…
Patch available
HIGH 8.7
CVE-2026-49741
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via Dat…
Patch available
HIGH 7.2
CVE-2026-47343
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of …
Patch available
HIGH 7.6
CVE-2026-47346
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form …
Patch available
MEDIUM 5.3
CVE-2026-47349
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify.…
Patch available
MEDIUM 5.3
CVE-2026-47350
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions…
Patch available
MEDIUM 5.3
CVE-2026-47351
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to …
Patch available
HIGH 7.6
CVE-2026-11607
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without den…
Patch available
MEDIUM 5.3
CVE-2026-4986
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing una…
Mitigation only
HIGH 7.5
CVE-2026-26236
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…
Qumagie
2.9.0+
MEDIUM 6.6
CVE-2026-44754
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permi…
Mitigation only
HIGH 7.1
CVE-2026-44751
Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation…
Mitigation only
CRITICAL 9.8
CVE-2026-39910
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to f…
Mitigation only
HIGH 8.8
CVE-2026-46444
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assist…
Flowise
3.1.2+
MEDIUM 5.3
CVE-2026-8502
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all …
Mitigation only