Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.3
CVE-2026-32101
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() functi…
Studiocms
0.3.1+
MEDIUM 6.5
CVE-2026-32102
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e…
Olivetin
after 3000.10.2
MEDIUM 6.5
CVE-2026-32108
Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulne…
Copyparty
1.20.12+
HIGH 7.5
CVE-2026-31887
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows…
Shopware
6.6.10.15 / 6.7.8.1+
HIGH 7.1
CVE-2026-30239
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned…
Openproject
17.2.0+
MEDIUM 6.5
CVE-2026-1471
Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte…
Neo4j
5.26.22 / 2026.01.4+
CRITICAL 9.8
CVE-2026-1524
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…
Neo4j
5.26.22 / 2026.02+
HIGH 8.1
CVE-2026-31892
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.1…
Argo Workflows
3.7.11 / 4.0.2+
HIGH 7.5
CVE-2026-28229
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow …
Argo Workflows
3.7.11 / 4.0.2+
HIGH 7.2
CVE-2026-1497
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following …
Neo4j
5.26.22 / 2026.02+
HIGH 8.8
CVE-2026-32059
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviati…
Openclaw
2026.2.23+
HIGH 7.5
CVE-2026-21309
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…
Commerce
1.3.3 / 2.4.4+
MEDIUM 5.3
CVE-2026-21286
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…
Commerce B2b
1.3.3 / 2.4.4+
HIGH 7.5
CVE-2026-21289
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…
Commerce B2b
1.3.3 / 2.4.4+
MEDIUM 5.3
CVE-2026-31838
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header mat…
Istio
1.27.8 / 1.28.5+
HIGH 7.7
CVE-2026-31801
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec a…
Zot
2.1.15+
CRITICAL 9.1
CVE-2026-30965
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerab…
Parse Server
8.6.21 / 9.5.2+
HIGH 7.5
CVE-2026-30947
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-leve…
Parse Server
8.6.16 / 9.5.2+
HIGH 8.2
CVE-2026-26308
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filte…
Envoy
1.34.13 / 1.35.8+
HIGH 8.8
CVE-2026-30944
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi…
Studiocms
0.4.0+
HIGH 7.1
CVE-2026-30945
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens…
Studiocms
0.4.0+
HIGH 7.8
CVE-2026-26141
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Azure Automation Hybrid Worker Windows Extension
1.3.74+
HIGH 7.1
CVE-2026-28513
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects…
Pocket Id
2.4.0+
CRITICAL 9.8
CVE-2026-30863
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, …
Parse Server
8.6.10 / 9.5.0+
MEDIUM 5.3
CVE-2026-30854
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version …
Parse Server
9.5.0+
MEDIUM 6.5
CVE-2026-29195
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an ad…
Netmaker
1.5.0+
HIGH 8.1
CVE-2026-29194
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a ro…
Netmaker
1.5.0+
HIGH 8.8
CVE-2026-30820
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that…
Flowise
3.0.13+
HIGH 8.2
CVE-2026-30241
Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscripti…
Mercurius
16.8.0+
HIGH 7.2
CVE-2026-30229
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, th…
Parse Server
8.6.6+