Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-3525
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)…
File Access Fix
8.x-1.2+
MEDIUM 5.3
CVE-2026-3526
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)…
File Access Fix
8.x-1.2+
MEDIUM 6.5
CVE-2026-33469
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can…
Frigate
No fix yet
MEDIUM 5.2
CVE-2026-33015
EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE c…
Everest
2026.02.0+
MEDIUM 5.2
CVE-2026-33014
EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorization response restores `author…
Everest
2026.02.0+
MEDIUM 6.5
CVE-2026-29044
EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, Au…
Everest
2026.02.0+
MEDIUM 6.5
CVE-2026-33343
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with R…
Etcd
3.4.42 / 3.5.28+
MEDIUM 5.4
CVE-2026-4274
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing memb…
Mattermost Server
10.11.11 / 11.2.3+
MEDIUM 6.9
CVE-2026-4263
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter
'visi…
Mitigation only
MEDIUM 6.9
CVE-2026-4262
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' i…
Mitigation only
MEDIUM 6.5
CVE-2026-33217
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs…
Nats Server
2.11.15 / 2.12.6+
MEDIUM 5.3
CVE-2026-33722
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external s…
N8n
1.123.23 / 2.6.4+
MEDIUM 5.3
CVE-2026-3210
Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4.
Material Icons
2.0.4+
HIGH 7.1
CVE-2026-33330
FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integrati…
Filerise
3.10.0+
MEDIUM 6.5
CVE-2026-33421
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, …
Parse Server
8.6.53 / 9.6.0+
HIGH 8.1
CVE-2026-33668
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disable…
Vikunja
2.2.1+
MEDIUM 6.5
CVE-2026-33676
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related…
Vikunja
2.2.1+
HIGH 8.1
CVE-2026-33316
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user…
Vikunja
2.2.0+
MEDIUM 5.4
CVE-2026-28755
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when c…
Nginx Plus
1.28.3 / 1.29.7+
HIGH 8.8
CVE-2026-4639
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform cert…
Vitalsesp
after 6.3
MEDIUM 5.3
CVE-2026-27183
OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attacker…
Openclaw
2026.3.7+
MEDIUM 6.1
CVE-2026-27646
OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to ini…
Openclaw
2026.3.7+
HIGH 7.6
CVE-2026-33650
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privil…
Avideo
after 26.0
HIGH 8.1
CVE-2026-32067
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing pol…
Openclaw
2026.2.26+
MEDIUM 5.4
CVE-2026-32895
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized …
Openclaw
2026.2.26+
MEDIUM 6.5
CVE-2026-32058
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p…
Openclaw
2026.2.26+
HIGH 8.8
CVE-2026-32051
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in…
Openclaw
2026.3.1+
MEDIUM 5.3
CVE-2026-32050
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender…
Openclaw
2026.2.25+
HIGH 8.8
CVE-2026-32042
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa…
Openclaw
2026.2.25+
MEDIUM 6.5
CVE-2026-33428
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group me…
Discourse
2026.1.2 / 2026.2.1+