Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.8 CVE-2026-35671 phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated ad… Mitigation only Fix from $1,9502026-05-28 HIGH 7.3 CVE-2026-9795 A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-42758 Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affe… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-42731 Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This i… Mitigation only Fix from $2,3002026-05-27 HIGH 7.3 CVE-2026-9580 A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDep… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-9581 A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation … Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-9579 A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the com… Mitigation only Fix from $1,6002026-05-26 HIGH 7.3 CVE-2026-9562 A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unkn… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9517 A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/… Mitigation only Fix from $1,9502026-05-26 HIGH 8.8 CVE-2026-45216 Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a thro… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.3 CVE-2026-9484 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStu… Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9483 A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing … Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9412 A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Exec… No fix yet Fix from $1,6002026-05-25 HIGH 8.1 CVE-2026-9397 A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the componen… Mitigation only Fix from $1,9502026-05-24 MEDIUM 6.3 CVE-2026-9376 A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the com… Mitigation only Fix from $1,6002026-05-24 HIGH 7.8 CVE-2025-32747 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access c… Powerflex Appliance Intelligent Catalog 3.7.8.0 / 48.383.00+ Fix from $1,9502026-05-22 CRITICAL 9.8 CVE-2026-48172 KEVEPSS 19% LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… Litespeed Cpanel Plugin 2.4.7 / 5.3.1.0+ Fix from $2,3002026-05-21 HIGH 7.2 CVE-2026-22315 Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user d… Mitigation only Fix from $1,9502026-05-20 MEDIUM 5.3 CVE-2026-8752 A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapid… H2o after 7402 Fix from $1,6002026-05-17 MEDIUM 6.3 CVE-2026-8747 A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of t… Mitigation only Fix from $1,6002026-05-17 MEDIUM 6.3 CVE-2026-8743 A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the compon… Open5gs after 2.7.6 Fix from $1,6002026-05-17 HIGH 7.5 CVE-2025-68420 Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is … Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-35062 An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technica… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-8241 A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of … Mitigation only Fix from $1,6002026-05-10 HIGH 7.8 CVE-2026-8148 NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation du… Mybox 3.0.11.160+ Fix from $1,9502026-05-08 MEDIUM 6.3 CVE-2026-8127 A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users… Mitigation only Fix from $1,6002026-05-08 MEDIUM 5.9 CVE-2026-43510 manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges … Patch available Fix from $1,6002026-05-07 HIGH 8.1 CVE-2026-43535 OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different sen… Openclaw 2026.4.14+ Fix from $1,9502026-05-05 CRITICAL 9.9 CVE-2026-42368 A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request ca… Gv Lpc2011 Firmware Mitigation only Fix from $2,3002026-05-04 MEDIUM 6.3 CVE-2026-7713 A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token … Patch available Fix from $1,6002026-05-04