Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-35029EPSS 26%
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce a…
Litellm
1.83.0+
CRITICAL 9.1
CVE-2026-5574
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr…
Hi Led Wr120 G2 Firmware
No fix yet
CRITICAL 9.1
CVE-2026-34953
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal …
Praisonai
4.5.97+
MEDIUM 6.3
CVE-2026-27447
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd…
Cups
after 2.4.16
MEDIUM 6.5
CVE-2025-68153
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope…
Juju
after 3.6.18
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
HIGH 7.5
CVE-2026-32173
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
Azure Sre Agent
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
HIGH 7.5
CVE-2026-34376
PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-con…
Pdfding
1.7.0+
HIGH 8.8
CVE-2025-71278
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version …
Xenforo
2.3.5+
HIGH 7.5
CVE-2026-34453
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected docum…
Siyuan
3.6.2+
MEDIUM 6.5
CVE-2026-34586
PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_…
Pdfding
1.7.1+
HIGH 8.1
CVE-2026-32726
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authoriz…
Scitokens Cpp Library
1.4.1+
CRITICAL 9.1
CVE-2026-34532
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, …
Parse Server
8.6.67 / 9.7.0+
MEDIUM 6.5
CVE-2026-33576
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can forc…
Openclaw
2026.3.28+
HIGH 8.1
CVE-2026-33577
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operato…
Openclaw
2026.3.28+
CRITICAL 9.9
CVE-2026-33579
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…
Openclaw
2026.3.28+
MEDIUM 6.5
CVE-2026-24029
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the AC…
Dnsdist
1.9.12 / 2.0.3+
HIGH 8.3
CVE-2026-0562
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging…
Lollms
after 2.1.0
HIGH 7.1
CVE-2026-32972
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to acce…
Openclaw
2026.3.11+
HIGH 7.5
CVE-2026-32978
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri…
Openclaw
2026.3.11+
HIGH 8.4
CVE-2026-32918
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent…
Openclaw
2026.3.11+
MEDIUM 6.1
CVE-2026-32919
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attac…
Openclaw
2026.3.11+
MEDIUM 5.4
CVE-2026-32923
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and r…
Openclaw
2026.3.11+
CRITICAL 9.8
CVE-2026-32924
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p…
Openclaw
2026.3.12+
HIGH 8.8
CVE-2026-32914
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-author…
Openclaw
2026.3.12+
HIGH 8.8
CVE-2026-32915
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolv…
Openclaw
2026.3.11+
MEDIUM 5.3
CVE-2026-34364
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category lis…
Avideo
after 26.0
HIGH 7.5
CVE-2026-4933
Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions…
Unpublished Node Permissions
8.x-1.7+
HIGH 7.5
CVE-2026-3573
Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence…
Artificial Intelligence
1.1.11 / 1.2.12+