Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-33353
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo…
Soft Serve
0.11.6+
CRITICAL 9.1
CVE-2026-33768
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par…
\@astrojs\/vercel
10.0.2+
MEDIUM 5.3
CVE-2026-33160
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …
Craft Cms
4.17.8 / 5.9.14+
MEDIUM 6.5
CVE-2026-33162
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c…
Craft Cms
5.9.14+
MEDIUM 6.5
CVE-2026-33159
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …
Craft Cms
4.17.8 / 5.9.14+
HIGH 8.1
CVE-2026-33316
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user…
Vikunja
2.2.0+
HIGH 7.5
CVE-2026-33484EPSS 6%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…
Langflow
1.9.0+
CRITICAL 9.1
CVE-2026-4283
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This i…
Mitigation only
MEDIUM 6.5
CVE-2026-3138
The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versi…
Mitigation only
MEDIUM 5.4
CVE-2026-4056
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the C…
Mitigation only
MEDIUM 5.3
CVE-2026-33685
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no auth…
Avideo
after 26.0
MEDIUM 5.3
CVE-2026-33501
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/li…
Avideo
after 26.0
HIGH 8.8
CVE-2026-4261
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin al…
Mitigation only
MEDIUM 5.3
CVE-2026-3651
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugi…
Mitigation only
MEDIUM 5.3
CVE-2026-3645
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_c…
Mitigation only
MEDIUM 5.3
CVE-2026-3570
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing aut…
Mitigation only
MEDIUM 5.3
CVE-2026-3506
The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the…
Mitigation only
MEDIUM 5.3
CVE-2026-3335
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/…
Mitigation only
HIGH 8.8
CVE-2026-2941
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'links…
Mitigation only
MEDIUM 6.5
CVE-2026-2720
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-…
Mitigation only
MEDIUM 5.3
CVE-2026-3567
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. T…
Mitigation only
MEDIUM 5.3
CVE-2026-33425
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe…
Discourse
2026.1.2 / 2026.2.1+
HIGH 7.5
CVE-2026-33427
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a…
Discourse
2026.1.2 / 2026.2.1+
CRITICAL 9.9
CVE-2026-22172
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…
Openclaw
2026.3.12+
MEDIUM 5.3
CVE-2026-3550
The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capabi…
Mitigation only
CRITICAL 9.8
CVE-2026-4038
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check…
Mitigation only
CRITICAL 9.1
CVE-2026-32817
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the curre…
Admidio
5.0.7+
MEDIUM 6.5
CVE-2026-32818
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current …
Admidio
5.0.7+
HIGH 7.5
CVE-2026-29072
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed …
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.5
CVE-2026-33304
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in…
Openemr
8.0.0.2+