Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-19670
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /au…
Fix unknown
MEDIUM 6.3
CVE-2026-55163
Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(ro…
Fix unknown
HIGH 8.8
CVE-2026-48508
Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p…
Fix unknown
HIGH 8.8
CVE-2026-61574
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo…
Fix unknown
HIGH 7.5
CVE-2026-74906
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…
Fix unknown
HIGH 8.3
CVE-2026-9816
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and arc…
Fix unknown
MEDIUM 6.5
CVE-2026-9859
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the …
Fix unknown
CRITICAL 9.6
CVE-2026-71424
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…
Fix unknown
MEDIUM 5.3
CVE-2026-11817
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-o…
Fix unknown
MEDIUM 6.5
CVE-2026-75480
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users …
Fix unknown
HIGH 7.5
CVE-2026-71518
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to acces…
Fix unknown
MEDIUM 6.2
CVE-2026-44846
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user…
Fix unknown
CRITICAL 9.9
CVE-2026-66792
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg…
Fix unknown
MEDIUM 6.3
CVE-2026-16048
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles w…
Mattermost Server
Fix unknown
MEDIUM 6.3
CVE-2026-10527
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which all…
Mattermost Server
Fix unknown
MEDIUM 5.4
CVE-2026-16044
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive impo…
Mattermost Server
Fix unknown
HIGH 7.0
CVE-2026-18674
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlP…
Fix unknown
MEDIUM 6.5
CVE-2026-73059
stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requ…
No fix yet
MEDIUM 6.5
CVE-2026-19726
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contribu…
Fix unknown
CRITICAL 9.8
CVE-2026-19598
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,…
No fix yet
HIGH 8.1
CVE-2026-19629
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission o…
No fix yet
HIGH 7.1
CVE-2026-49989
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they …
No fix yet
HIGH 7.7
CVE-2026-72859
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 …
No fix yet
MEDIUM 5.8
CVE-2026-73049
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden a…
No fix yet
HIGH 8.8
CVE-2026-72831
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiCo…
No fix yet
HIGH 8.8
CVE-2026-73841
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an…
No fix yet
HIGH 8.8
CVE-2026-73305
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…
No fix yet
HIGH 7.7
CVE-2026-72672
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data …
No fix yet
MEDIUM 5.4
CVE-2026-72673
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properl…
No fix yet
HIGH 7.1
CVE-2026-72643
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to…
No fix yet