Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-41654
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS …
Weblate
5.17.1+
MEDIUM 5.4
CVE-2026-41519
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via…
Weblate
5.17.1+
MEDIUM 5.0
CVE-2026-40256
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolu…
Weblate
5.17+
HIGH 8.8
CVE-2026-34393
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This is…
Weblate
5.17+
HIGH 8.0
CVE-2026-33435
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which cou…
Weblate
5.17+
HIGH 7.7
CVE-2026-34242
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following …
Weblate
5.17+
MEDIUM 6.8
CVE-2026-33220
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe…
Weblate
5.17+
MEDIUM 5.0
CVE-2026-33440
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and …
Weblate
5.17+
MEDIUM 5.0
CVE-2026-34244
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat…
Weblate
5.17+
CRITICAL 9.1
CVE-2026-24126
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key…
Weblate
5.16+
HIGH 8.0
CVE-2026-23535
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location w…
Wlc
1.17.2+
HIGH 7.5
CVE-2026-21889
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access contro…
Weblate
5.15.2+
MEDIUM 5.5
CVE-2026-22250
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vul…
Wlc
1.17.0+
MEDIUM 5.5
CVE-2026-22251
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practi…
Wlc
1.17.0+
CRITICAL 9.1
CVE-2025-68398
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i…
Weblate
5.15.1+
MEDIUM 6.5
CVE-2025-68279
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf…
Weblate
5.15.1+
MEDIUM 5.3
CVE-2025-67492
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafte…
Weblate
5.15+
MEDIUM 5.0
CVE-2025-66407
Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by …
Weblate
5.15+
CRITICAL 9.8
CVE-2025-64725
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15…
Weblate
5.15+
MEDIUM 6.1
CVE-2025-61587
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblat…
Weblate
5.13.3+
MEDIUM 6.5
CVE-2025-58352
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second facto…
Weblate
5.13.1+
MEDIUM 5.3
CVE-2025-49134
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This co…
Weblate
5.12+
HIGH 7.5
CVE-2025-32021
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repo…
Weblate
5.11+
MEDIUM 5.4
CVE-2024-39303
Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may b…
Weblate
5.6.2+
HIGH 8.8
CVE-2022-23915
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial reposit…
Weblate
4.11.1+
MEDIUM 5.4
CVE-2022-24710
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user na…
Weblate
4.11+
MEDIUM 5.3
CVE-2017-5537
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an accou…
Weblate
after 2.10