Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2026-62323
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI acc…
No fix yet
HIGH 7.1
CVE-2026-55502
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even …
No fix yet
HIGH 7.7
CVE-2026-14538
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…
Mcp Toolbox For Databases
after 1.4.0
CRITICAL 9.8
CVE-2026-14537
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated at…
Mcp Toolbox For Databases
No fix yet
MEDIUM 6.6
CVE-2026-65835
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…
No fix yet
MEDIUM 6.8
CVE-2026-67347
Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.se…
No fix yet
MEDIUM 6.5
CVE-2026-41187
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,…
Calico
3.21.7 / 3.22.4+
MEDIUM 6.5
CVE-2026-14923
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and u…
No fix yet
CRITICAL 9.8
CVE-2026-48449
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …
Campaign
after 7.4.2
MEDIUM 6.5
CVE-2026-65975
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.…
Pydantic Ai
1.107.1 / 2.5.0+
MEDIUM 5.3
CVE-2026-6336
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …
GitLab
19.0.5 / 19.1.3+
CRITICAL 9.3
CVE-2026-18236
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in…
No fix yet
HIGH 8.2
CVE-2026-54693
ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email …
No fix yet
HIGH 7.2
CVE-2026-18255
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a membe…
No fix yet
HIGH 8.5
CVE-2026-44944
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects…
No fix yet
HIGH 8.2
CVE-2026-58159
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic Server: from…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2025-10656
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u…
No fix yet
MEDIUM 5.3
CVE-2026-66064
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened f…
No fix yet
HIGH 7.5
CVE-2026-54719
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?…
No fix yet
HIGH 8.2
CVE-2026-48390
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili…
Bridge
15.1.7 / 16.0.6+
HIGH 8.6
CVE-2026-48396
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An a…
Bridge
15.1.7 / 16.0.6+
MEDIUM 6.5
CVE-2026-7868
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrat…
No fix yet
HIGH 8.8
CVE-2026-14167
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management du…
No fix yet
HIGH 7.1
CVE-2026-43672
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26…
macOS
14.8.8 / 15.7.8+
HIGH 8.8
CVE-2026-42016
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signa…
Artifactory
7.133.11+
HIGH 8.8
CVE-2026-17568
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the …
Devolutions Server
2026.1.24.0 / 2026.2.14.0+
MEDIUM 6.3
CVE-2026-17529
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The …
No fix yet
MEDIUM 6.3
CVE-2026-17530
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the…
No fix yet
HIGH 8.0
CVE-2026-59689
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF all…
Connection Manager For Objectscale
7.2.54.19 / 7.2.63.3+
HIGH 8.1
CVE-2026-8789
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver…
No fix yet