Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2026-21036
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.
Internet
30.0.0.39+
HIGH 7.8
CVE-2026-21031
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required f…
Android
Mitigation only
MEDIUM 5.4
CVE-2026-42547
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users…
Mitigation only
HIGH 8.6
CVE-2026-41235
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell li…
Mitigation only
MEDIUM 6.3
CVE-2026-10815
A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown …
Mitigation only
MEDIUM 6.5
CVE-2026-10860
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to …
Misp
2.5.39+
CRITICAL 9.9
CVE-2026-41283
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which…
Mitigation only
HIGH 7.4
CVE-2025-14774
Incorrect Authorization vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
T Mac Plus
Mitigation only
HIGH 8.1
CVE-2026-44654
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete f…
Librechat
0.8.5+
CRITICAL 9.1
CVE-2026-35482
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca…
Alf
2.0-M5-2606+
HIGH 7.5
CVE-2026-3514
In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health …
Prefect
3.6.22+
HIGH 7.8
CVE-2025-32348
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privi…
Android
Mitigation only
CRITICAL 9.1
CVE-2026-22872
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR…
Capsule
0.13.0+
MEDIUM 6.3
CVE-2026-10211
A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tool…
Mitigation only
MEDIUM 6.5
CVE-2026-49376
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Teamcity
2026.1+
CRITICAL 9.1
CVE-2026-48501
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF …
Cli
2.93.0+
MEDIUM 6.5
CVE-2026-35673
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t…
Openclaw
2026.4.29+
HIGH 8.8
CVE-2026-35674
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma…
Openclaw
2026.5.18+
MEDIUM 5.4
CVE-2026-34507
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF…
Openclaw
2026.4.29+
HIGH 7.1
CVE-2026-9808
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured wi…
Mitigation only
MEDIUM 5.3
CVE-2026-49299
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined polic…
Mitigation only
HIGH 8.5
CVE-2026-44850
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…
Portainer
2.33.8 / 2.39.1+
HIGH 8.1
CVE-2026-44882
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…
Portainer
2.33.8+
HIGH 7.7
CVE-2026-46823
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versio…
Public Sector Financials
after 12.2.15
MEDIUM 5.3
CVE-2026-42070
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update…
Patch available
HIGH 8.1
CVE-2026-44394
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…
Keystone
27.0.2 / 28.0.2+
HIGH 7.1
CVE-2026-45042
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows cop…
Mitigation only
HIGH 8.8
CVE-2026-42998
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …
Keystone
27.0.2 / 28.0.2+
HIGH 8.8
CVE-2026-42999
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…
Keystone
27.0.2 / 28.0.2+
HIGH 8.8
CVE-2026-43000
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…
Keystone
27.0.2 / 28.0.2+