Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Filebrowser HIGH 8.8
CVE-2026-35607

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Fix: after 2.63.0
Fix from $1,950 2026-04-07
Runzero Platform HIGH 8.4
CVE-2026-5373

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Impr…

Fix: 4.0.260202.0+
Fix from $1,950 2026-04-07
Pi Hole MEDIUM 6.7
CVE-2026-33727

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability …

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.8
CVE-2023-7343

Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an …

Mitigation only
Fix from $1,950 2026-04-02
macOS HIGH 8.2
CVE-2024-44250

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary co…

Fix: 15.1+
Fix from $1,950 2026-04-02
Unclassified HIGH 8.8
CVE-2023-7342

HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or a…

Mitigation only
Fix from $1,950 2026-04-02
Filebrowser CRITICAL 9.8
CVE-2026-34528

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…

Fix: 2.62.2+
Fix from $2,300 2026-04-01
Himmelblau HIGH 7.0
CVE-2026-34397

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before …

Fix: 2.3.9 / 3.1.1+
Fix from $1,950 2026-04-01
Discourse MEDIUM 5.3
CVE-2026-33074

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Clearancekit MEDIUM 5.5
CVE-2026-34218

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup def…

Fix: 4.2.14+
Fix from $1,600 2026-03-31
Ella Core HIGH 7.2
CVE-2026-33906

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The …

Fix: 1.7.0+
Fix from $1,950 2026-03-27
Unclassified HIGH 8.8
CVE-2026-2931

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to th…

Mitigation only
Fix from $1,950 2026-03-26
Crun HIGH 7.8
CVE-2026-30892

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectl…

Fix: 1.27+
Fix from $1,950 2026-03-26
Unclassified HIGH 7.0
CVE-2026-4824

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Ba…

Mitigation only
Fix from $1,950 2026-03-25
Osslsigncode CRITICAL 9.8
CVE-2025-70888

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

Fix: after 2.10
Fix from $2,300 2026-03-25
Signify HIGH 8.8
CVE-2025-70887

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

Fix: 0.9.2+
Fix from $1,950 2026-03-25
Xcode MEDIUM 6.2
CVE-2026-28889

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.

Fix: 26.4+
Fix from $1,600 2026-03-25
Pyload Ng HIGH 8.8
CVE-2026-33509

pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API e…

Fix: 0.5.0b3.dev97+
Fix from $1,950 2026-03-24
Vikunja CRITICAL 9.6
CVE-2026-33334

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…

Fix: 2.2.2+
Fix from $2,300 2026-03-24
Systemd MEDIUM 5.5
CVE-2026-29111

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. …

Fix: 257.11 / 258.5+
Fix from $1,600 2026-03-23
Unclassified HIGH 8.8
CVE-2026-4314

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3…

Mitigation only
Fix from $1,950 2026-03-22
Unclassified HIGH 8.1
CVE-2026-3629

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. Th…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.5
CVE-2026-2375

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an…

Mitigation only
Fix from $1,600 2026-03-21
Checkmate HIGH 8.1
CVE-2026-31836

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with …

Fix: after 3.5.1
Fix from $1,950 2026-03-20
Discourse MEDIUM 5.5
CVE-2026-30888

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy do…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-20
Filebrowser CRITICAL 9.8
CVE-2026-32760

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions …

Fix: 2.62.0+
Fix from $2,300 2026-03-20
Openwrt HIGH 7.8
CVE-2026-30874

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function al…

Fix: 24.10.6+
Fix from $1,950 2026-03-19
Wazuh HIGH 7.2
CVE-2026-25770

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, …

Fix: 4.14.3+
Fix from $1,950 2026-03-17
Studiocms HIGH 7.2
CVE-2026-32106

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-b…

Fix: 0.4.3+
Fix from $1,950 2026-03-11
Unclassified MEDIUM 5.5
CVE-2026-2640

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to …

Mitigation only
Fix from $1,600 2026-03-11