Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-72900
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
No fix yet
CRITICAL 9.6
CVE-2026-72737
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …
No fix yet
MEDIUM 5.3
CVE-2026-72723
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_men…
No fix yet
CRITICAL 9.3
CVE-2026-47754
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta…
No fix yet
MEDIUM 6.9
CVE-2026-72759
In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record…
No fix yet
MEDIUM 5.8
CVE-2026-71959
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing…
No fix yet
HIGH 7.5
CVE-2026-72692
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline…
No fix yet
MEDIUM 6.5
CVE-2026-19404
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization …
No fix yet
MEDIUM 5.3
CVE-2026-17021
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does…
No fix yet
HIGH 8.1
CVE-2026-18030
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one…
No fix yet
MEDIUM 5.4
CVE-2026-14941
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX act…
No fix yet
MEDIUM 5.3
CVE-2026-15237
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payme…
No fix yet
MEDIUM 6.3
CVE-2026-19350
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta…
No fix yet
MEDIUM 6.5
CVE-2026-19345
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip…
No fix yet
MEDIUM 6.5
CVE-2026-18603
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding …
No fix yet
MEDIUM 6.5
CVE-2026-18037
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and…
No fix yet
MEDIUM 6.5
CVE-2026-16992
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r…
No fix yet
MEDIUM 5.3
CVE-2026-16608
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the…
No fix yet
MEDIUM 6.5
CVE-2026-47127
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/sub…
No fix yet
HIGH 8.8
CVE-2026-48169
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…
No fix yet
MEDIUM 5.7
CVE-2026-64676
Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the …
No fix yet
HIGH 7.1
CVE-2026-66060
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links …
No fix yet
HIGH 7.1
CVE-2026-66061
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag lin…
No fix yet
MEDIUM 6.8
CVE-2026-19017
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault…
No fix yet
MEDIUM 5.3
CVE-2026-66058
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss…
No fix yet
HIGH 8.9
CVE-2026-17601
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader per…
No fix yet
MEDIUM 6.9
CVE-2026-54201
Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks
when serving these log files. As a result, attacke…
No fix yet
HIGH 7.5
CVE-2026-16041
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route,…
No fix yet
MEDIUM 6.5
CVE-2026-15359
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers…
No fix yet
CRITICAL 9.1
CVE-2026-16038
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its…
No fix yet