Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.8
CVE-2026-72799
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPa…
No fix yet
MEDIUM 5.8
CVE-2026-72800
SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retr…
No fix yet
HIGH 8.6
CVE-2026-72789
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous re…
No fix yet
MEDIUM 5.8
CVE-2026-72790
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata wi…
No fix yet
MEDIUM 5.8
CVE-2026-72791
SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in th…
No fix yet
CRITICAL 9.9
CVE-2026-63300
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c…
No fix yet
CRITICAL 9.9
CVE-2026-19656
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil…
No fix yet
HIGH 7.1
CVE-2026-16494
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could…
No fix yet
CRITICAL 9.4
CVE-2026-73296
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and…
No fix yet
MEDIUM 5.9
CVE-2026-69107
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
No fix yet
MEDIUM 6.5
CVE-2026-68971
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68758
A low-privileged authenticated user may access restricted support information under specific conditions.
No fix yet
MEDIUM 5.3
CVE-2026-73405
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) strea…
No fix yet
MEDIUM 5.4
CVE-2026-73287
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/s…
No fix yet
MEDIUM 6.5
CVE-2026-73265
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP…
No fix yet
MEDIUM 6.5
CVE-2026-68754
A repository publisher without delete permission may modify protected package content under specific conditions.
No fix yet
MEDIUM 5.3
CVE-2026-68753
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
No fix yet
HIGH 8.1
CVE-2026-66375
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
No fix yet
MEDIUM 5.3
CVE-2026-66377
An unauthenticated user may access restricted repository information under specific conditions.
No fix yet
MEDIUM 6.5
CVE-2026-47233
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modu…
No fix yet
MEDIUM 6.5
CVE-2026-47226
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can…
No fix yet
HIGH 7.0
CVE-2026-53996
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i…
No fix yet
HIGH 7.5
CVE-2026-18789
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated atta…
No fix yet
MEDIUM 5.3
CVE-2026-18035
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attacker…
No fix yet
HIGH 8.2
CVE-2026-64954
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT…
No fix yet
HIGH 7.5
CVE-2026-73249
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/…
No fix yet
HIGH 8.2
CVE-2026-48763
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b…
No fix yet
HIGH 8.8
CVE-2026-15606
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…
No fix yet
MEDIUM 6.5
CVE-2026-69115
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints …
No fix yet
MEDIUM 6.5
CVE-2026-18704
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co…
No fix yet