Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Nocobase HIGH 7.2
CVE-2026-41641

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQ…

Fix: 2.0.39+
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-8033

A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ …

Mitigation only
Fix from $1,600 2026-05-06
Iot Field Network Director HIGH 7.7
CVE-2026-20167

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv…

Fix: 5.0.0-117+
Fix from $1,950 2026-05-06
Flowise MEDIUM 5.3
CVE-2026-8026

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv…

Fix: after 3.0.12
Fix from $1,600 2026-05-06
Unclassified HIGH 7.5
CVE-2024-52911

Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.

No fix yet
Fix from $1,950 2026-05-05
Nginx Ui CRITICAL 9.8
CVE-2026-42222

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified HIGH 8.1
CVE-2025-67796

IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. T…

Mitigation only
Fix from $1,950 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7733

A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7732

A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.ph…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7711

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wra…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7696

A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function …

Mitigation only
Fix from $1,600 2026-05-03
Unclassified MEDIUM 5.3
CVE-2026-7686

A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium…

Mitigation only
Fix from $1,600 2026-05-03
Automotive Grade Linux HIGH 7.8
CVE-2026-37526

AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config,…

Fix: after 17.1.12
Fix from $1,950 2026-05-01
I CRITICAL 9.8
CVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified MEDIUM 6.5
CVE-2026-40603

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified HIGH 8.1
CVE-2026-40904

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 7.5
CVE-2026-40595

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 7.3
CVE-2026-7468

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 8.8
CVE-2026-5141

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research…

Mitigation only
Fix from $1,950 2026-04-29
Minerva HIGH 8.8
CVE-2026-5779

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. T…

Mitigation only
Fix from $1,950 2026-04-28
Minerva HIGH 8.1
CVE-2026-5780

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vul…

Mitigation only
Fix from $1,950 2026-04-28
Spring Ai MEDIUM 5.9
CVE-2026-40966

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and c…

Fix: 1.0.6 / 1.1.5+
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7107

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7044

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulati…

Mitigation only
Fix from $1,600 2026-04-26
Unclassified MEDIUM 6.3
CVE-2026-7043

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. T…

Mitigation only
Fix from $1,600 2026-04-26
Unclassified MEDIUM 6.5
CVE-2025-67259

A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized cour…

Mitigation only
Fix from $1,600 2026-04-24
Actual HIGH 8.8
CVE-2026-33318

Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se…

Fix: 26.4.0+
Fix from $1,950 2026-04-24
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
Flowise HIGH 8.8
CVE-2026-41277

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the Docum…

Fix: 3.1.0+
Fix from $1,950 2026-04-23