Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Unclassified HIGH 8.2
CVE-2026-57768

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-57410

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-57386

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through …

No fix yet
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15509

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulati…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15510

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in im…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15499

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 5.3
CVE-2026-15476

A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of …

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 5.3
CVE-2026-15475

A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15473

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAc…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15376

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15373

A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15374

A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the componen…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.3
CVE-2026-15319

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/a…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-15271

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by th…

Mitigation only
Fix from $1,950 2026-07-09
Dir 823g Firmware HIGH 7.5
CVE-2026-15270

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15188

A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is t…

Mitigation only
Fix from $1,600 2026-07-09
Cmc HIGH 8.1
CVE-2026-33390

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An …

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Command Centre MEDIUM 5.3
CVE-2026-26053

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to pe…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.5
CVE-2026-14792

A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts …

Patch available
Fix from $1,600 2026-07-06
Unclassified HIGH 7.3
CVE-2026-14778

A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the …

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.3
CVE-2026-14719

A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file r…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified MEDIUM 5.4
CVE-2026-14693

A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_orde…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified HIGH 7.3
CVE-2026-14690

A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file …

No fix yet
Fix from $1,950 2026-07-05
Weaviate HIGH 8.8
CVE-2026-59093

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The as…

Fix: 1.38.0+
Fix from $1,950 2026-07-02
Satellite HIGH 8.8
CVE-2026-5136

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This …

Fix: 3.18.2 / 3.19.1+
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a throug…

Mitigation only
Fix from $2,300 2026-07-01
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53902

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.8
CVE-2026-56247

Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pendin…

Mitigation only
Fix from $1,950 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role …

No fix yet
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-12388

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is …

Mitigation only
Fix from $1,600 2026-06-30