Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
MEDIUM 6.3 CVE-2026-7709 A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_au… Mitigation only Fix from $1,6002026-05-03 MEDIUM 5.3 CVE-2026-7686 A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium… Mitigation only Fix from $1,6002026-05-03 HIGH 7.3 CVE-2026-7644 A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The man… Mitigation only Fix from $1,9502026-05-02 MEDIUM 5.4 CVE-2026-7631 A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Regist… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7602 A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the … Mitigation only Fix from $1,6002026-05-02 HIGH 7.3 CVE-2026-7505 A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This man… Patch available Fix from $1,9502026-04-30 HIGH 7.3 CVE-2026-7468 A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/… Mitigation only Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-5141 Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research… Mitigation only Fix from $1,9502026-04-29 MEDIUM 5.6 CVE-2026-7292 A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAge… Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7142 A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of t… Patch available Fix from $1,6002026-04-27 CRITICAL 9.8 CVE-2026-22337 Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Socia… Mitigation only Fix from $2,3002026-04-27 MEDIUM 5.3 CVE-2026-7109 A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API … No fix yet Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7091 A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Manage… Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7092 A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component… Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7093 A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /inv… Mitigation only Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-6977 A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask A… Mitigation only Fix from $1,9502026-04-25 HIGH 7.2 CVE-2026-33518 An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to cre… Portal For Arcgis Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-33519 An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly… Portal For Arcgis Mitigation only Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-40869 Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any regist… Decidim 0.30.5 / 0.31.1+ Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-6750 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund… Firefox 115.35.0 / 140.10.0+ Fix from $1,9502026-04-21 MEDIUM 6.3 CVE-2026-6634 A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component … Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6609 A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This mani… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.6 CVE-2026-6572 A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app… Mitigation only Fix from $1,6002026-04-19 HIGH 8.8 CVE-2026-27668 A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowe… Mitigation only Fix from $1,9502026-04-14 MEDIUM 5.4 CVE-2026-6201 A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of th… Mitigation only Fix from $1,6002026-04-13 HIGH 7.3 CVE-2026-6105 A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/… Mitigation only Fix from $1,9502026-04-11 MEDIUM 6.3 CVE-2026-5999 A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulati… Mitigation only Fix from $1,6002026-04-10 HIGH 7.8 CVE-2026-27102 Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerabi… Powerscale Onefs 9.10.1.7 / 9.13.0.2+ Fix from $1,9502026-04-08 HIGH 7.3 CVE-2026-5642 A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown functio… Mitigation only Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-5569 A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the componen… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05