Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-29182
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Pa…
Parse Server
8.6.4+
HIGH 7.5
CVE-2026-29087
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving togeth…
Node Server
1.19.10+
HIGH 8.1
CVE-2026-23925
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can le…
Zabbix
6.0.41 / 7.0.18+
MEDIUM 6.5
CVE-2026-28715
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)…
Cyber Protect
17.0.41186+
HIGH 8.1
CVE-2026-28473
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec ap…
Openclaw
2026.2.2+
CRITICAL 9.8
CVE-2026-28474
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid…
Openclaw
2026.2.6+
CRITICAL 9.9
CVE-2026-28466
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2026-28392
OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any …
Openclaw
2026.2.14+
HIGH 7.5
CVE-2026-28790
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…
Olivetin
3000.11.0+
MEDIUM 5.3
CVE-2026-21621
Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation.
An API key cr…
Hexpm
2026-03-05+
HIGH 8.1
CVE-2026-3009
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…
Build Of Keycloak
Mitigation only
HIGH 7.8
CVE-2026-29127
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…
Sfx2100 Firmware
No fix yet
HIGH 7.8
CVE-2026-29126
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver al…
Sfx2100 Firmware
No fix yet
HIGH 8.3
CVE-2026-27802
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privile…
Vaultwarden
1.35.4+
HIGH 8.3
CVE-2026-27803
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has…
Vaultwarden
1.35.4+
HIGH 7.8
CVE-2026-26949
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local …
Device Management Agent
26.02+
MEDIUM 5.4
CVE-2026-3103
A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user…
Checkmk
Mitigation only
MEDIUM 5.4
CVE-2025-13734
IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…
Engineering Requirements Management Doors Next
Mitigation only
CRITICAL 9.8
CVE-2026-3136
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut…
Cloud Build
2026-1-26+
MEDIUM 6.5
CVE-2026-28354
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,…
Clipbucket
5.5.3-59+
CRITICAL 9.8
CVE-2026-2293
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio…
Nest
Mitigation only
MEDIUM 6.5
CVE-2025-9572
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, …
Satellite
3.16.2+
MEDIUM 6.7
CVE-2026-27653
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary …
Securebrowser For Onegate
1.4.8 / 2.0.15+
HIGH 7.1
CVE-2026-25741
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card updat…
Patch available
HIGH 7.5
CVE-2026-26265
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en…
Discourse
2025.12.0 / 2026.1.1+
MEDIUM 6.5
CVE-2026-25963
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion A…
Fleet
4.80.1+
HIGH 8.8
CVE-2026-27899
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-ad…
Wireguard Portal
2.1.3+
MEDIUM 6.5
CVE-2026-24487
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp…
Openemr
8.0.0+
CRITICAL 9.1
CVE-2026-27607
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…
Rustfs
Mitigation only
MEDIUM 6.5
CVE-2026-25127
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not …
Openemr
8.0.0+