Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2026-72630
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to m…
No fix yet
HIGH 7.1
CVE-2026-73652
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an…
No fix yet
CRITICAL 9.1
CVE-2026-58443
Public-only repository tokens can update private PR head branches
No fix yet
MEDIUM 6.5
CVE-2026-57897
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
No fix yet
HIGH 7.1
CVE-2026-58416
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
No fix yet
HIGH 7.5
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
No fix yet
HIGH 8.1
CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
No fix yet
CRITICAL 9.6
CVE-2026-56443
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
No fix yet
HIGH 8.1
CVE-2026-24791
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
No fix yet
HIGH 8.1
CVE-2026-70463
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp…
No fix yet
HIGH 7.4
CVE-2026-70452
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS …
No fix yet
MEDIUM 6.5
CVE-2026-53786
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supp…
No fix yet
HIGH 8.8
CVE-2026-49473
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by ma…
No fix yet
CRITICAL 9.6
CVE-2026-71193
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe…
No fix yet
HIGH 7.1
CVE-2026-73499
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permissi…
No fix yet
MEDIUM 5.8
CVE-2026-72788
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator wo…
No fix yet
MEDIUM 5.8
CVE-2026-72792
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts f…
No fix yet
CRITICAL 9.9
CVE-2026-63296
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m…
No fix yet
CRITICAL 9.9
CVE-2026-63297
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj…
No fix yet
CRITICAL 9.9
CVE-2026-62420
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins…
No fix yet
HIGH 8.5
CVE-2026-15423
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …
No fix yet
HIGH 8.1
CVE-2026-73286
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request he…
No fix yet
HIGH 8.1
CVE-2026-73289
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifie…
No fix yet
MEDIUM 5.3
CVE-2026-73290
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/ac…
No fix yet
MEDIUM 6.5
CVE-2026-73265
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP…
No fix yet
HIGH 7.5
CVE-2026-73285
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTF…
No fix yet
MEDIUM 5.7
CVE-2026-18171
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge g…
No fix yet
MEDIUM 6.5
CVE-2026-47230
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same ro…
No fix yet
HIGH 8.1
CVE-2026-47231
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking tha…
No fix yet
MEDIUM 6.5
CVE-2026-47227
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, ……
No fix yet