Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.4
CVE-2026-18709
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa…
No fix yet
MEDIUM 5.4
CVE-2026-69113
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on…
No fix yet
HIGH 8.8
CVE-2026-70340
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Azure Cyclecloud
No fix yet
MEDIUM 6.5
CVE-2026-65806
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Azure Cyclecloud
No fix yet
MEDIUM 6.5
CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Exchange Server
15.02.2562.046+
MEDIUM 5.5
CVE-2026-61936
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
HIGH 8.8
CVE-2026-59113
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
No fix yet
MEDIUM 6.5
CVE-2026-40375
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Dynamics 365 Business Central 2024
26.0.50788 / 27.0.50789+
HIGH 7.1
CVE-2026-48495
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trus…
No fix yet
HIGH 7.1
CVE-2026-42142
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate worksp…
No fix yet
HIGH 8.6
CVE-2026-19539
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated use…
No fix yet
MEDIUM 5.3
CVE-2026-73140
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal commen…
No fix yet
MEDIUM 5.3
CVE-2026-73155
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users …
No fix yet
MEDIUM 6.5
CVE-2026-14548
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…
No fix yet
HIGH 8.8
CVE-2026-58243
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe…
No fix yet
HIGH 7.3
CVE-2026-44764
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted …
No fix yet
HIGH 7.3
CVE-2026-44765
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access…
No fix yet
MEDIUM 5.9
CVE-2026-58237
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t…
No fix yet
HIGH 8.7
CVE-2025-30237
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certa…
No fix yet
MEDIUM 5.4
CVE-2026-72918
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.…
No fix yet
HIGH 7.1
CVE-2026-72910
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job…
No fix yet
HIGH 8.5
CVE-2026-18947
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec…
No fix yet
HIGH 8.8
CVE-2026-72883
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/…
No fix yet
CRITICAL 9.9
CVE-2026-72876
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA…
No fix yet
HIGH 8.2
CVE-2026-14886
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call…
No fix yet
CRITICAL 9.9
CVE-2026-72864
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve…
No fix yet
HIGH 8.8
CVE-2026-72866
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validat…
No fix yet
CRITICAL 9.9
CVE-2026-72868
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce…
No fix yet
CRITICAL 9.9
CVE-2026-72863
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…
No fix yet
HIGH 7.5
CVE-2026-71962
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that …
No fix yet