Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-11907
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not prop…
No fix yet
CRITICAL 9.8
CVE-2026-14365
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…
No fix yet
CRITICAL 10.0
CVE-2026-65667
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 9.9
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Azure Sre Agent
No fix yet
HIGH 7.5
CVE-2026-70636
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh e…
No fix yet
HIGH 7.6
CVE-2026-67621
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto…
No fix yet
MEDIUM 6.5
CVE-2026-64662
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con…
No fix yet
CRITICAL 9.8
CVE-2026-48085
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision…
No fix yet
CRITICAL 9.4
CVE-2026-48088
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /…
No fix yet
MEDIUM 5.3
CVE-2026-48077
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler a…
No fix yet
MEDIUM 6.5
CVE-2026-48075
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunne…
No fix yet
HIGH 7.1
CVE-2026-47765
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate …
No fix yet
MEDIUM 6.0
CVE-2026-45415
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_censu…
No fix yet
HIGH 7.5
CVE-2026-13399
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau…
No fix yet
HIGH 7.1
CVE-2026-18277
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to gran…
Escriptorium
No fix yet
HIGH 7.5
CVE-2026-66712
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
No fix yet
HIGH 8.2
CVE-2026-66708
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
No fix yet
MEDIUM 5.3
CVE-2026-66699
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
No fix yet
MEDIUM 5.3
CVE-2026-66701
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66452
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
No fix yet
HIGH 7.1
CVE-2026-66470
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
No fix yet
HIGH 7.1
CVE-2026-65554
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
No fix yet
HIGH 7.3
CVE-2026-65541
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
No fix yet
HIGH 7.5
CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-32548
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
No fix yet
HIGH 7.5
CVE-2026-28140
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
No fix yet
MEDIUM 6.5
CVE-2026-25403
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
No fix yet
HIGH 7.5
CVE-2026-65551
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects…
No fix yet
MEDIUM 5.3
CVE-2026-11983
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du…
No fix yet