Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-33251
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability i…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 5.4
CVE-2026-33291
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets f…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 5.4
CVE-2026-33312
Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:…
Vikunja
2.2.0+
MEDIUM 5.3
CVE-2026-33132
ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforce…
Zitadel
3.4.9 / 4.12.3+
HIGH 8.2
CVE-2026-31805
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu…
Discourse
2026.1.2 / 2026.2.1+
HIGH 7.5
CVE-2026-32811
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with version…
Heimdall
0.17.11+
CRITICAL 9.8
CVE-2026-32767
SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS…
Siyuan
3.6.1+
MEDIUM 6.5
CVE-2026-32758
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…
Filebrowser
2.62.0+
MEDIUM 6.5
CVE-2026-32761
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…
Filebrowser
2.62.0+
MEDIUM 5.4
CVE-2026-33410
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the cha…
Discourse
2026.1.2 / 2026.2.1+
HIGH 7.1
CVE-2026-32035
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t…
Openclaw
2026.3.2+
MEDIUM 6.5
CVE-2026-32027
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for gro…
Openclaw
2026.2.26+
MEDIUM 5.3
CVE-2026-32028
OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, al…
Openclaw
2026.2.25+
MEDIUM 6.5
CVE-2026-32021
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts muta…
Openclaw
2026.2.22+
HIGH 7.1
CVE-2026-32023
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch w…
Openclaw
2026.2.24+
MEDIUM 5.4
CVE-2026-32001
OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to …
Openclaw
2026.2.22+
HIGH 8.1
CVE-2026-32005
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, a…
Openclaw
2026.2.22+
MEDIUM 5.3
CVE-2026-27936
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted …
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.5
CVE-2026-28282
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-po…
Discourse
2026.1.2 / 2026.2.1+
HIGH 8.1
CVE-2026-33302
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `A…
Openemr
8.0.0.2+
HIGH 8.6
CVE-2026-31998
OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to all…
Openclaw
2026.2.24+
HIGH 8.8
CVE-2026-32693
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th…
Juju
3.6.19+
MEDIUM 6.5
CVE-2026-22170
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom config…
Openclaw
2026.2.22+
CRITICAL 9.8
CVE-2026-32267EPSS 8%
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, …
Craft Cms
4.17.6 / 5.9.12+
MEDIUM 6.5
CVE-2025-69196
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter…
Fastmcp
2.14.2+
MEDIUM 6.6
CVE-2026-2462
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default ad…
Mattermost Server
10.11.11 / 11.2.3+
HIGH 7.5
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515…
Pyjwt
2.12.0+
MEDIUM 6.5
CVE-2026-32245
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authori…
Tinyauth
after 5.0.2
MEDIUM 6.3
CVE-2026-3977
A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. T…
Patch available
MEDIUM 6.5
CVE-2026-32123
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for gro…
Openemr
8.0.0.1+