Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-5574
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr…
Hi Led Wr120 G2 Firmware
No fix yet
HIGH 7.1
CVE-2026-3445
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…
Mitigation only
MEDIUM 6.5
CVE-2026-3571
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a…
Mitigation only
MEDIUM 5.4
CVE-2026-34766
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…
Electron
38.8.6 / 39.8.0+
HIGH 7.5
CVE-2026-27833
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered wi…
Piwigo
16.3.0+
CRITICAL 9.8
CVE-2026-35561
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow …
Athena Odbc
2.1.0.0+
MEDIUM 5.3
CVE-2026-25742
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before…
Zulip
11.6+
HIGH 7.5
CVE-2026-22663
prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and …
Prompts.chat
2026-03-25+
HIGH 8.1
CVE-2026-34759
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered witho…
Oneuptime
10.0.42+
CRITICAL 9.4
CVE-2026-33950
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…
Signal K Server
2.24.0+
HIGH 8.0
CVE-2026-20155
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attac…
Evolved Programmable Network Manager
8.1.2+
MEDIUM 5.0
CVE-2026-5175
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete thei…
Devolutions Server
2026.1.12.0+
MEDIUM 5.0
CVE-2026-4925
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and…
Devolutions Server
2026.1.12.0+
MEDIUM 6.5
CVE-2026-34737
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible …
Avideo
after 26.0
MEDIUM 6.5
CVE-2026-34395
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform user…
Avideo
after 26.0
HIGH 8.1
CVE-2026-4818
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage…
Flx
4.1.0+
MEDIUM 5.3
CVE-2026-1797
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,…
Mitigation only
HIGH 8.2
CVE-2026-34042
act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connection…
Patch available
MEDIUM 5.4
CVE-2025-15445
The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in…
Mitigation only
HIGH 8.8
CVE-2026-34046
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l…
Langflow Base
0.5.1 / 1.5.0+
MEDIUM 5.4
CVE-2026-33887
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could v…
Statamic
5.73.16 / 6.7.2+
HIGH 8.8
CVE-2026-29180
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team ma…
Fleet
4.81.1+
MEDIUM 5.3
CVE-2026-34369
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVi…
Avideo
after 26.0
MEDIUM 6.3
CVE-2026-34245
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endp…
Avideo
after 26.0
MEDIUM 5.4
CVE-2026-34247
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authentica…
Avideo
after 26.0
MEDIUM 5.3
CVE-2026-5022
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated u…
Langflow
Mitigation only
MEDIUM 6.5
CVE-2026-5025
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only…
Langflow
Mitigation only
MEDIUM 5.3
CVE-2026-33759
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full …
Avideo
after 26.0
MEDIUM 5.3
CVE-2026-33761
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any …
Avideo
after 26.0
MEDIUM 6.5
CVE-2026-4309
Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the setting…
Aterm Wg2600hs Firmware
1.3.2 / 1.4.2+