Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-41477
Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with …
Deskflow
after 1.26.0.161
MEDIUM 5.3
CVE-2026-3569
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-pr…
Mitigation only
MEDIUM 5.3
CVE-2026-5347
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of…
Mitigation only
MEDIUM 5.3
CVE-2026-5488
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and includi…
Mitigation only
HIGH 8.8
CVE-2026-33318
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se…
Actual
26.4.0+
HIGH 8.1
CVE-2026-40623
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suff…
X3500 Firmware
Mitigation only
HIGH 8.8
CVE-2026-41352
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec…
Openclaw
2026.3.31+
HIGH 8.8
CVE-2026-41349
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc…
Openclaw
2026.3.28+
HIGH 7.5
CVE-2026-41266
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …
Flowise
3.1.0+
HIGH 7.2
CVE-2026-5464
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugi…
Mitigation only
CRITICAL 10.0
CVE-2026-41679
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…
Paperclipai
2026.416.0+
HIGH 8.3
CVE-2026-41454
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to per…
Patch available
HIGH 8.3
CVE-2026-40937
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src…
Rustfs
Mitigation only
CRITICAL 9.8
CVE-2026-6235
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up …
Mitigation only
MEDIUM 5.3
CVE-2026-4117
The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability c…
Mitigation only
CRITICAL 9.1
CVE-2026-4119
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin…
Mitigation only
MEDIUM 6.5
CVE-2026-6834
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database conten…
Mitigation only
MEDIUM 5.3
CVE-2026-41128
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `vie…
Patch available
HIGH 7.5
CVE-2026-40870
Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field…
Mitigation only
HIGH 7.1
CVE-2026-41192
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted att…
Patch available
MEDIUM 5.9
CVE-2026-40592
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}…
Patch available
MEDIUM 5.7
CVE-2026-40570
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` …
Patch available
HIGH 8.8
CVE-2026-39386
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…
Neko
3.0.11 / 3.1.2+
MEDIUM 5.4
CVE-2026-41298
OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped ca…
Openclaw
2026.4.2+
MEDIUM 5.4
CVE-2026-40098
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…
Magento
20.17.0+
HIGH 7.5
CVE-2026-25058
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector se…
Vexa
after 0.10
HIGH 8.1
CVE-2026-40581
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs per…
Patch available
HIGH 8.8
CVE-2026-40349
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their…
Movary
0.71.1+
HIGH 7.1
CVE-2026-40480
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person re…
Patch available
HIGH 7.6
CVE-2026-40474
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.ch…
Wger
2.5+