Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Wekan MEDIUM 5.3
CVE-2026-1964

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1963

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage…

Fix: 8.21+
Fix from $2,300 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1962

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp…

Fix: 8.21+
Fix from $2,300 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1898

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1896

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 5.4
CVE-2026-1894

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe…

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan MEDIUM 6.3
CVE-2026-1895

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han…

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan MEDIUM 5.0
CVE-2026-1892

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-04
Pet Grooming Management Software HIGH 8.8
CVE-2026-1702

A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/use…

No fix yet
Fix from $1,950 2026-01-30
Saleserp HIGH 8.8
CVE-2026-1597

A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint…

No fix yet
Fix from $1,950 2026-01-29
Hospital Management System HIGH 8.8
CVE-2026-1550

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /h…

No fix yet
Fix from $1,950 2026-01-28
777vr1 Firmware MEDIUM 6.1
CVE-2026-1411

A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This …

Fix: after 01.00.09_55
Fix from $1,600 2026-01-26
Unclassified HIGH 8.8
CVE-2025-69292

Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: f…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69293

Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a t…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69182

Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affect…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69183

Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-68869

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue aff…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 7.3
CVE-2025-68027

Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: fr…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-67966

Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Dir…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.1
CVE-2025-67953

Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-50007

Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSmart: from n/a through <= 1.2.…

Mitigation only
Fix from $1,950 2026-01-22
Mineadmin HIGH 8.8
CVE-2026-1193

A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View…

No fix yet
Fix from $1,950 2026-01-19
News Portal HIGH 8.8
CVE-2026-1141

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the…

No fix yet
Fix from $1,950 2026-01-19
Publiccms HIGH 8.1
CVE-2026-1112

A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public…

Fix: after 5.202506.d
Fix from $1,950 2026-01-18
Chamilo Lms MEDIUM 5.4
CVE-2026-1106

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control…

Fix: 2.0.0+
Fix from $1,600 2026-01-18
Unclassified CRITICAL 10.0
CVE-2026-23800

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 be…

Mitigation only
Fix from $2,300 2026-01-16
Unclassified MEDIUM 6.2
CVE-2021-47799

Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root…

No fix yet
Fix from $1,600 2026-01-15
Tdc X401gl Firmware MEDIUM 6.5
CVE-2026-22914

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

No fix yet
Fix from $1,600 2026-01-15
Tdc X401gl Firmware MEDIUM 5.4
CVE-2026-22916

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potenti…

Mitigation only
Fix from $1,600 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22907

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

Fix: 1.4.0+
Fix from $2,300 2026-01-15