Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.2 CVE-2026-57768 Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57410 Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: … Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57386 Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through … No fix yet Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15509 A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulati… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15510 A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in im… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15499 A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/… Mitigation only Fix from $1,6002026-07-12 MEDIUM 5.3 CVE-2026-15476 A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of … Mitigation only Fix from $1,6002026-07-12 MEDIUM 5.3 CVE-2026-15475 A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15473 A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAc… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15376 A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15373 A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15374 A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the componen… Mitigation only Fix from $1,6002026-07-10 HIGH 7.3 CVE-2026-15319 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/a… Patch available Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-15271 A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by th… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-15270 A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/… Dir 823g Firmware Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15188 A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is t… Mitigation only Fix from $1,6002026-07-09 HIGH 8.1 CVE-2026-33390 An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An … Cmc 26.2.0+ Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-26053 An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to pe… Command Centre Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-14792 A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts … Patch available Fix from $1,6002026-07-06 HIGH 7.3 CVE-2026-14778 A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the … Mitigation only Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-14719 A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file r… Mitigation only Fix from $1,9502026-07-05 MEDIUM 5.4 CVE-2026-14693 A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_orde… Mitigation only Fix from $1,6002026-07-05 HIGH 7.3 CVE-2026-14690 A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file … No fix yet Fix from $1,9502026-07-05 HIGH 8.8 CVE-2026-59093 Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The as… Weaviate 1.38.0+ Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-5136 A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This … Satellite 3.18.2 / 3.19.1+ Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-57692 Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a throug… Mitigation only Fix from $2,3002026-07-01 MEDIUM 6.5 CVE-2026-53902 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 HIGH 8.8 CVE-2026-56247 Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pendin… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-4629 A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role … Build Of Keycloak No fix yet Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-12388 A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is … Build Of Keycloak Mitigation only Fix from $1,6002026-06-30