Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
CRITICAL 9.8 CVE-2026-5526 A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionali… 4g03 Pro Firmware Mitigation only Fix from $2,3002026-04-04 MEDIUM 5.3 CVE-2026-5484 A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormat… Patch available Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2026-5330 A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the … Mitigation only Fix from $1,6002026-04-02 MEDIUM 5.3 CVE-2026-5312 A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dns 1550 04 Firmware after 2026-02-05 Fix from $1,6002026-04-01 MEDIUM 5.3 CVE-2026-5311 A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326… Dnr 202l Firmware after 2026-02-05 Fix from $1,6002026-04-01 MEDIUM 5.3 CVE-2026-5215 A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dnr 202l Firmware after 2026-02-05 Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-32916 OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug… Openclaw 2026.3.11+ Fix from $2,3002026-03-31 HIGH 8.1 CVE-2026-33997 Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validat… Engine 29.3.1+ Fix from $1,9502026-03-31 CRITICAL 9.9 CVE-2026-32922 OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min… Openclaw 2026.3.11+ Fix from $2,3002026-03-29 HIGH 7.3 CVE-2026-4990 A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the compon… Mitigation only Fix from $1,9502026-03-27 HIGH 7.2 CVE-2026-3121 A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to… Build Of Keycloak Mitigation only Fix from $1,9502026-03-26 HIGH 7.0 CVE-2026-4824 A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Ba… Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-32530 Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.0 CVE-2026-32519 Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-32520 Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects Rewards… Mitigation only Fix from $2,3002026-03-25 HIGH 8.1 CVE-2026-32488 Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Reg… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-27051 Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. Mitigation only Fix from $2,3002026-03-25 HIGH 8.8 CVE-2026-25414 Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: f… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-25334 Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issu… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-24971 Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24968 Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a thro… Mitigation only Fix from $2,3002026-03-25 HIGH 8.1 CVE-2026-24373 Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege… Mitigation only Fix from $1,9502026-03-25 MEDIUM 5.8 CVE-2026-1712 Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server: from 10.5.1 before 10.7. Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-20110 A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an a… Mitigation only Fix from $1,6002026-03-25 HIGH 7.3 CVE-2026-4617 A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToke… Mitigation only Fix from $1,9502026-03-24 MEDIUM 6.3 CVE-2026-4548 A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file ac… Mitigation only Fix from $1,6002026-03-22 MEDIUM 6.3 CVE-2026-4514 A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserCon… Mitigation only Fix from $1,6002026-03-21 CRITICAL 9.8 CVE-2026-27542 Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-4194 A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-3… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16 HIGH 7.5 CVE-2026-4193 A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetD… Dir 823g Firmware No fix yet Fix from $1,9502026-03-16