Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-3143
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data…
Mitigation only
HIGH 7.5
CVE-2026-40601
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char…
Mitigation only
MEDIUM 5.3
CVE-2026-42642
Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…
Mitigation only
MEDIUM 5.3
CVE-2026-4019
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 T…
Mitigation only
MEDIUM 6.5
CVE-2026-42412
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue a…
Mitigation only
HIGH 7.3
CVE-2026-42377
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels.
This …
Mitigation only
HIGH 8.2
CVE-2026-41394
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime writ…
Openclaw
2026.3.31+
MEDIUM 5.4
CVE-2026-41382
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member …
Openclaw
2026.3.31+
HIGH 8.8
CVE-2026-41378
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests wi…
Openclaw
2026.3.31+
MEDIUM 6.5
CVE-2026-6706
Improper
access control in the vault documentation feature in Devolutions
Server allows an authenticated attacker to read documentation content
fr…
Devolutions Server
2025.3.19.0 / 2026.1.15.0+
HIGH 8.2
CVE-2026-5944
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth…
Intersight Device Connector
after 7.5.0
CRITICAL 9.1
CVE-2026-40976
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v…
Spring Boot
4.0.6+
MEDIUM 6.5
CVE-2026-41464
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users …
Mitigation only
HIGH 7.8
CVE-2026-41477
Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with …
Deskflow
after 1.26.0.161
MEDIUM 5.3
CVE-2026-3569
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-pr…
Mitigation only
MEDIUM 5.3
CVE-2026-5347
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of…
Mitigation only
MEDIUM 5.3
CVE-2026-5488
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and includi…
Mitigation only
HIGH 8.8
CVE-2026-33318
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se…
Actual
26.4.0+
HIGH 8.1
CVE-2026-40623
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suff…
X3500 Firmware
Mitigation only
HIGH 8.8
CVE-2026-41352
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec…
Openclaw
2026.3.31+
HIGH 8.8
CVE-2026-41349
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc…
Openclaw
2026.3.28+
HIGH 7.5
CVE-2026-41266
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …
Flowise
3.1.0+
HIGH 7.2
CVE-2026-5464
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugi…
Mitigation only
CRITICAL 10.0
CVE-2026-41679
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…
Paperclipai
2026.416.0+
HIGH 8.3
CVE-2026-41454
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to per…
Patch available
HIGH 8.3
CVE-2026-40937
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src…
Rustfs
Mitigation only
CRITICAL 9.8
CVE-2026-6235
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up …
Mitigation only
MEDIUM 5.3
CVE-2026-4117
The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability c…
Mitigation only
CRITICAL 9.1
CVE-2026-4119
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin…
Mitigation only
MEDIUM 6.5
CVE-2026-6834
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database conten…
Mitigation only