Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.9
CVE-2026-42604
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full …
Mitigation only
MEDIUM 6.9
CVE-2026-50008
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al…
Patch available
MEDIUM 5.3
CVE-2026-44173
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…
MariaDB
10.6.26 / 10.11.17+
HIGH 7.2
CVE-2026-6739
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin…
Mattermost Server
10.11.17 / 11.5.5+
HIGH 8.8
CVE-2026-7387
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz…
Mattermost Server
10.11.17 / 11.5.5+
HIGH 8.8
CVE-2026-45831
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a…
Chromadb
after 1.5.9
HIGH 8.2
CVE-2026-53721
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule m…
Nuxt
3.21.7 / 4.4.7+
HIGH 7.1
CVE-2026-47195
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking me…
Mitigation only
MEDIUM 6.5
CVE-2026-47238
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt…
Mitigation only
HIGH 8.8
CVE-2026-53807
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com…
Openclaw
2026.5.6+
MEDIUM 6.5
CVE-2026-53808
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:…
Openclaw
2026.5.6+
HIGH 8.8
CVE-2026-46519
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes thr…
Mitigation only
MEDIUM 5.4
CVE-2026-6269
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…
GitLab
18.10.8 / 18.11.5+
MEDIUM 5.5
CVE-2026-49219
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect…
Imagemagick
6.9.13-48 / 7.1.2-24+
HIGH 8.1
CVE-2026-53738
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers wi…
Mitigation only
HIGH 7.2
CVE-2026-0272
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int…
Pan Os
10.2.7 / 10.2.10+
HIGH 7.7
CVE-2026-49823
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 8.5
CVE-2026-49824
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
MEDIUM 6.5
CVE-2026-48860
Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-ov…
Erlang\/otp
11.2.12.9 / 11.6.0.2+
CRITICAL 9.1
CVE-2026-45550
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo…
Mitigation only
CRITICAL 9.9
CVE-2026-45552
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares …
Mitigation only
HIGH 8.5
CVE-2026-45549
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/a…
Mitigation only
HIGH 8.1
CVE-2026-24724
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit…
File Station
5.5.6.5243+
CRITICAL 10.0
CVE-2026-48303
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi…
Campaign
7.4.3+
HIGH 8.4
CVE-2026-47929
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code executio…
Coldfusion
Mitigation only
MEDIUM 6.3
CVE-2026-47910
Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read.…
Dreamweaver
21.8+
HIGH 7.8
CVE-2026-45490
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
.net
8.0.28 / 9.0.17+
MEDIUM 5.3
CVE-2026-41852
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or…
Spring Framework
5.3.49 / 6.1.28+
HIGH 7.1
CVE-2026-48507
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `user…
Snipe It
8.6.0+
MEDIUM 5.3
CVE-2026-7765
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creat…
Checkmk
Mitigation only