Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2026-27344
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.Th…
Mitigation only
HIGH 7.5
CVE-2026-27361
Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Confi…
Mitigation only
MEDIUM 6.5
CVE-2026-23799
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…
Mitigation only
HIGH 7.5
CVE-2026-22479
Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Se…
Mitigation only
MEDIUM 6.5
CVE-2026-22459
Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security…
Mitigation only
HIGH 7.5
CVE-2025-69340
Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorre…
Mitigation only
MEDIUM 6.5
CVE-2026-2899
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is du…
Mitigation only
MEDIUM 6.5
CVE-2026-1674
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized…
Mitigation only
MEDIUM 5.4
CVE-2026-2732
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBa…
Patch available
CRITICAL 9.8
CVE-2026-3266
Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF t…
Filr
25.1.3+
MEDIUM 5.4
CVE-2025-13734
IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…
Engineering Requirements Management Doors Next
Mitigation only
MEDIUM 5.3
CVE-2026-1336
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to mi…
Mitigation only
HIGH 7.8
CVE-2026-0026
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code…
Android
Mitigation only
HIGH 7.3
CVE-2025-48634
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala…
Android
Mitigation only
HIGH 8.4
CVE-2025-48574
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che…
Android
Mitigation only
HIGH 7.8
CVE-2025-48578
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec…
Android
Mitigation only
CRITICAL 9.8
CVE-2026-3431
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos…
Sim
0.5.74+
CRITICAL 9.1
CVE-2026-3432
On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided …
Sim
0.5.74+
MEDIUM 5.4
CVE-2026-28556
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via…
Wpforo Forum
2.4.16+
MEDIUM 6.5
CVE-2026-28557
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment v…
Wpforo Forum
2.4.16+
MEDIUM 6.5
CVE-2026-28424
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in re…
Statamic
5.73.11 / 6.4.0+
HIGH 8.8
CVE-2026-28515
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The install…
Opendcim
Patch available
CRITICAL 9.8
CVE-2026-28408
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…
Wegia
3.6.5+
HIGH 7.5
CVE-2026-27836
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active u…
Phpmyfaq
4.0.18+
MEDIUM 5.4
CVE-2026-27792
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified i…
Seerr
3.1.0+
HIGH 7.5
CVE-2026-28276
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded…
Initiative
0.32.2+
MEDIUM 6.5
CVE-2026-28217
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…
Hoppscotch
2026.2.0+
HIGH 7.1
CVE-2026-27638
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify …
Actual
26.2.1+
MEDIUM 5.3
CVE-2026-27021
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked p…
Discourse
2025.12.0 / 2026.1.1+
MEDIUM 5.4
CVE-2026-26207
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authentica…
Discourse
2025.12.0 / 2026.1.1+