Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
MEDIUM 5.3 CVE-2026-1964 A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi… Wekan 8.21+ Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2026-1963 A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage… Wekan 8.21+ Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-1962 A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp… Wekan 8.21+ Fix from $2,3002026-02-05 MEDIUM 6.3 CVE-2026-1898 A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component … Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 6.3 CVE-2026-1896 A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig… Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 5.4 CVE-2026-1894 A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe… Wekan 8.21+ Fix from $1,6002026-02-04 MEDIUM 6.3 CVE-2026-1895 A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han… Wekan 8.21+ Fix from $1,6002026-02-04 MEDIUM 5.0 CVE-2026-1892 A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component … Wekan 8.21+ Fix from $1,6002026-02-04 HIGH 8.8 CVE-2026-1702 A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/use… Pet Grooming Management Software No fix yet Fix from $1,9502026-01-30 HIGH 8.8 CVE-2026-1597 A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint… Saleserp No fix yet Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-1550 A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /h… Hospital Management System No fix yet Fix from $1,9502026-01-28 MEDIUM 6.1 CVE-2026-1411 A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This … 777vr1 Firmware after 01.00.09_55 Fix from $1,6002026-01-26 HIGH 8.8 CVE-2025-69292 Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: f… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69293 Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a t… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69182 Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affect… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69183 Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue … Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2025-68869 Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue aff… Mitigation only Fix from $2,3002026-01-22 HIGH 7.3 CVE-2025-68027 Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: fr… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-67966 Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Dir… Mitigation only Fix from $1,9502026-01-22 HIGH 8.1 CVE-2025-67953 Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue … Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-50007 Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSmart: from n/a through <= 1.2.… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2026-1193 A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View… Mineadmin No fix yet Fix from $1,9502026-01-19 HIGH 8.8 CVE-2026-1141 A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the… News Portal No fix yet Fix from $1,9502026-01-19 HIGH 8.1 CVE-2026-1112 A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public… Publiccms after 5.202506.d Fix from $1,9502026-01-18 MEDIUM 5.4 CVE-2026-1106 A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control… Chamilo Lms 2.0.0+ Fix from $1,6002026-01-18 CRITICAL 10.0 CVE-2026-23800 Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 be… Mitigation only Fix from $2,3002026-01-16 MEDIUM 6.2 CVE-2021-47799 Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root… No fix yet Fix from $1,6002026-01-15 MEDIUM 6.5 CVE-2026-22914 An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation. Tdc X401gl Firmware No fix yet Fix from $1,6002026-01-15 MEDIUM 5.4 CVE-2026-22916 An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potenti… Tdc X401gl Firmware Mitigation only Fix from $1,6002026-01-15 CRITICAL 9.1 CVE-2026-22907 An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data. Tdc X401gl Firmware 1.4.0+ Fix from $2,3002026-01-15