Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
4g03 Pro Firmware CRITICAL 9.8
CVE-2026-5526

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionali…

Mitigation only
Fix from $2,300 2026-04-04
Unclassified MEDIUM 5.3
CVE-2026-5484

A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormat…

Patch available
Fix from $1,600 2026-04-03
Unclassified MEDIUM 6.5
CVE-2026-5330

A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the …

Mitigation only
Fix from $1,600 2026-04-02
Dns 1550 04 Firmware MEDIUM 5.3
CVE-2026-5312

A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $1,600 2026-04-01
Dnr 202l Firmware MEDIUM 5.3
CVE-2026-5311

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326…

Fix: after 2026-02-05
Fix from $1,600 2026-04-01
Dnr 202l Firmware MEDIUM 5.3
CVE-2026-5215

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $1,600 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32916

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug…

Fix: 2026.3.11+
Fix from $2,300 2026-03-31
Engine HIGH 8.1
CVE-2026-33997

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validat…

Fix: 29.3.1+
Fix from $1,950 2026-03-31
Openclaw CRITICAL 9.9
CVE-2026-32922

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min…

Fix: 2026.3.11+
Fix from $2,300 2026-03-29
Unclassified HIGH 7.3
CVE-2026-4990

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the compon…

Mitigation only
Fix from $1,950 2026-03-27
Build Of Keycloak HIGH 7.2
CVE-2026-3121

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 7.0
CVE-2026-4824

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Ba…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 8.8
CVE-2026-32530

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.0
CVE-2026-32519

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-32520

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects Rewards…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.1
CVE-2026-32488

Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Reg…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-27051

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.8
CVE-2026-25414

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: f…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 8.1
CVE-2026-25334

Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issu…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24971

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24968

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a thro…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.1
CVE-2026-24373

Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 5.8
CVE-2026-1712

Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server: from 10.5.1 before 10.7.

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-20110

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an a…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 7.3
CVE-2026-4617

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToke…

Mitigation only
Fix from $1,950 2026-03-24
Unclassified MEDIUM 6.3
CVE-2026-4548

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file ac…

Mitigation only
Fix from $1,600 2026-03-22
Unclassified MEDIUM 6.3
CVE-2026-4514

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserCon…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified CRITICAL 9.8
CVE-2026-27542

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P…

Mitigation only
Fix from $2,300 2026-03-19
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4194

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-3…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dir 823g Firmware HIGH 7.5
CVE-2026-4193

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetD…

No fix yet
Fix from $1,950 2026-03-16