Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-15704
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon…
No fix yet
CRITICAL 9.9
CVE-2026-15630
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…
No fix yet
HIGH 7.1
CVE-2026-59678
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the net…
No fix yet
MEDIUM 6.3
CVE-2026-13067
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configur…
MongoDB
8.0.28 / 8.3.7+
MEDIUM 6.5
CVE-2026-13060
An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an incons…
MongoDB
7.0.39 / 8.0.28+
HIGH 8.8
CVE-2026-65601
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spe…
Traefik
3.7.7+
HIGH 8.8
CVE-2026-65602
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTranspo…
Traefik
3.6.23 / 3.7.7+
MEDIUM 6.5
CVE-2026-65594
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify …
N8n
2.29.8+
HIGH 8.1
CVE-2026-65596
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic…
N8n
1.123.64 / 2.29.8+
HIGH 8.8
CVE-2026-65015
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authoriza…
N8n
2.29.8+
MEDIUM 5.0
CVE-2026-63142
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound …
Kibana
8.19.19 / 9.3.8+
HIGH 7.6
CVE-2026-61325
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is af…
Advanced Benefits
No fix yet
HIGH 7.1
CVE-2026-61012
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected…
Time And Labor
after 12.2.15
HIGH 8.1
CVE-2026-60951
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected…
Time And Labor
after 12.2.15
HIGH 8.4
CVE-2026-60723
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are …
Data Integrator
No fix yet
CRITICAL 9.9
CVE-2026-60663
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 7.8
CVE-2026-60625
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions that are affected are 12.2.1…
Data Integrator
No fix yet
HIGH 7.5
CVE-2026-60320
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affecte…
Data Integrator
No fix yet
HIGH 8.9
CVE-2026-43945
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to ach…
Mitigation only
HIGH 7.7
CVE-2026-43946
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint …
No fix yet
HIGH 8.9
CVE-2026-43947
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability wh…
No fix yet
HIGH 7.1
CVE-2026-47697
Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, seve…
No fix yet
MEDIUM 6.5
CVE-2026-56144
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorizatio…
Elasticsearch
8.19.18 / 9.3.7+
MEDIUM 5.4
CVE-2026-56146
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential informati…
Kibana
9.4.3+
CRITICAL 9.4
CVE-2026-47407
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un…
No fix yet
HIGH 8.6
CVE-2026-15829
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of…
No fix yet
CRITICAL 9.3
CVE-2026-65049
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administr…
Mitigation only
HIGH 8.8
CVE-2026-59851
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ…
Hardened Images
No fix yet
MEDIUM 6.1
CVE-2026-47128
nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow acce…
No fix yet
MEDIUM 6.3
CVE-2026-64650
The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to vers…
No fix yet