Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-40099
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…
Kirby
4.9.0 / 5.4.0+
HIGH 8.8
CVE-2026-41325
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…
Kirby
4.9.0 / 5.4.0+
MEDIUM 5.4
CVE-2026-41348
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group D…
Openclaw
2026.3.31+
HIGH 8.8
CVE-2026-41344
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist…
Openclaw
2026.3.28+
MEDIUM 6.5
CVE-2026-41908
OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without op…
Openclaw
2026.4.20+
MEDIUM 5.4
CVE-2026-41909
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to …
Openclaw
2026.4.20+
MEDIUM 5.0
CVE-2026-41232
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full emai…
Froxlor
2.3.6+
MEDIUM 5.4
CVE-2026-41233
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user inpu…
Froxlor
2.3.6+
MEDIUM 5.0
CVE-2026-41131
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with cach…
Helm Charts
0.3.1 / 1.14.1+
HIGH 7.1
CVE-2026-40599
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats …
Clearancekit
5.0.5+
HIGH 7.1
CVE-2026-41189
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::…
Patch available
HIGH 7.1
CVE-2026-41190
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direc…
Patch available
HIGH 7.1
CVE-2026-41191
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new`…
Patch available
MEDIUM 6.8
CVE-2026-40574
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy …
Oauth2 Proxy
7.15.2+
MEDIUM 6.6
CVE-2026-26274
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox securit…
Mitigation only
HIGH 8.8
CVE-2026-41303
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pendi…
Openclaw
2026.3.28+
HIGH 8.1
CVE-2026-33031
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously iss…
Nginx Ui
2.3.4+
MEDIUM 6.5
CVE-2025-13480
Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protec…
Fudo Enterprise
5.6.3+
HIGH 7.8
CVE-2026-39454
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A …
Skymec It Manager
after 2024.005.10a
HIGH 7.5
CVE-2026-32228
UI / API User with asset materialize permission could trigger dags they had no access to.
Users are advised to migrate to Airflow version 3.2.0 that …
Airflow
3.2.0+
HIGH 8.8
CVE-2026-40350
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the use…
Movary
0.71.1+
MEDIUM 5.3
CVE-2026-40304
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contai…
Zrok
2.0.1+
MEDIUM 5.4
CVE-2026-40155
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ…
Nextjs Auth0
4.18.0+
MEDIUM 5.5
CVE-2026-40515
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete p…
Openharness
2026-04-11+
MEDIUM 5.3
CVE-2026-24749
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rend…
Mitigation only
MEDIUM 5.4
CVE-2026-39350
Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1,…
Istio
1.27.9 / 1.28.6+
MEDIUM 5.3
CVE-2026-33888
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get…
Apostrophecms
4.29.0+
MEDIUM 5.4
CVE-2026-6383
A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names,…
Mitigation only
HIGH 8.4
CVE-2026-4857
IdentityIQ 8.5, all
IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ
8.4 patch levels prior to 8.4p4 allow authenticate…
Mitigation only
CRITICAL 9.1
CVE-2026-6290
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…
Velociraptor
0.76.3+