Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.2
CVE-2026-13738
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res…
No fix yet
HIGH 8.6
CVE-2025-30238
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
oper…
No fix yet
CRITICAL 9.9
CVE-2026-72886
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…
No fix yet
HIGH 8.8
CVE-2026-69118
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut…
No fix yet
MEDIUM 6.9
CVE-2026-21076
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
No fix yet
MEDIUM 6.9
CVE-2026-21077
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
No fix yet
MEDIUM 5.5
CVE-2026-18934
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named …
No fix yet
MEDIUM 5.3
CVE-2026-15229
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated user…
No fix yet
MEDIUM 6.3
CVE-2026-19350
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta…
No fix yet
MEDIUM 6.5
CVE-2026-19345
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip…
No fix yet
HIGH 7.1
CVE-2026-45808
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A t…
No fix yet
HIGH 8.2
CVE-2026-17594
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user in…
No fix yet
MEDIUM 5.3
CVE-2026-66059
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. …
No fix yet
MEDIUM 5.9
CVE-2026-37171
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, da…
No fix yet
HIGH 7.8
CVE-2026-7867
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option …
No fix yet
MEDIUM 5.3
CVE-2026-71433
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the …
No fix yet
MEDIUM 6.5
CVE-2026-48076
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1…
No fix yet
MEDIUM 5.1
CVE-2026-47185
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authent…
No fix yet
HIGH 8.5
CVE-2026-45414
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th…
No fix yet
MEDIUM 6.5
CVE-2026-64640
Apache Polaris did not consistently validate storage locations supplied during table and view registration.
An authenticated principal with permissi…
Polaris
after 1.6.0
HIGH 7.3
CVE-2026-19010
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c…
No fix yet
MEDIUM 6.3
CVE-2026-19006
A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Gg…
No fix yet
MEDIUM 6.3
CVE-2026-18997
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/…
No fix yet
MEDIUM 6.3
CVE-2026-18992
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec…
No fix yet
CRITICAL 9.8
CVE-2026-52466
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ…
No fix yet
HIGH 8.2
CVE-2026-71315
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-f…
No fix yet
MEDIUM 5.5
CVE-2026-18954
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie…
Documentdb Mcp Server
1.0.12+
MEDIUM 6.5
CVE-2026-50749
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary…
Answer
2.0.2+
MEDIUM 6.5
CVE-2026-71247
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b…
No fix yet
HIGH 7.5
CVE-2026-71234
Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a…
No fix yet