Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-64952
The hunt_delete() VQL function allows deleting hunts.
Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned …
No fix yet
HIGH 7.1
CVE-2026-63177
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…
No fix yet
MEDIUM 5.3
CVE-2026-73221
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use…
No fix yet
HIGH 8.1
CVE-2026-18712
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio…
No fix yet
MEDIUM 5.4
CVE-2026-18698
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
MEDIUM 6.5
CVE-2026-18696
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti…
No fix yet
HIGH 8.1
CVE-2026-18690
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…
No fix yet
CRITICAL 9.3
CVE-2026-73090
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…
No fix yet
MEDIUM 5.8
CVE-2026-73213
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-…
No fix yet
CRITICAL 10.0
CVE-2026-71398
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
CRITICAL 9.1
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…
No fix yet
HIGH 7.7
CVE-2026-48447
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…
Lightroom
15.5+
HIGH 7.6
CVE-2026-48415
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker coul…
No fix yet
HIGH 7.5
CVE-2026-48416
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
No fix yet
MEDIUM 6.5
CVE-2026-48411
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileg…
No fix yet
CRITICAL 10.0
CVE-2026-27302
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
No fix yet
HIGH 7.3
CVE-2026-71383
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…
No fix yet
CRITICAL 9.6
CVE-2026-71384
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…
No fix yet
HIGH 8.8
CVE-2026-71387
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …
No fix yet
HIGH 7.8
CVE-2026-69278
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
1.132.1+
MEDIUM 6.5
CVE-2026-63512
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Sharepoint Server
16.0.19725.20522+
HIGH 8.8
CVE-2026-62872
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
.net Framework
No fix yet
MEDIUM 5.5
CVE-2026-62775
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
Windows 11 26h1
10.0.28000.2704+
HIGH 7.8
CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1607
No fix yet
MEDIUM 6.5
CVE-2026-48375
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c…
Coldfusion
No fix yet
HIGH 7.8
CVE-2026-25652
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulne…
Coldfusion
No fix yet
HIGH 8.1
CVE-2026-72921
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.…
No fix yet
HIGH 7.2
CVE-2026-18635
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, t…
No fix yet
HIGH 7.1
CVE-2026-72771
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin…
No fix yet
CRITICAL 9.2
CVE-2026-13737
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance …
No fix yet