Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Weblogic Server HIGH 7.2
CVE-2026-34292

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2026-04-21
Identity Manager Connector MEDIUM 5.9
CVE-2026-34294

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported v…

Mitigation only
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Scm Purchasing MEDIUM 6.5
CVE-2026-34295

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affec…

Mitigation only
Fix from $1,600 2026-04-21
Identity Manager Connector CRITICAL 9.1
CVE-2026-34287

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
HTTP Server HIGH 8.7
CVE-2026-34291

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 a…

Mitigation only
Fix from $1,950 2026-04-21
Identity Manager MEDIUM 6.1
CVE-2026-34283

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected…

Mitigation only
Fix from $1,600 2026-04-21
Business Process Management Suite MEDIUM 6.1
CVE-2026-34284

Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versio…

Mitigation only
Fix from $1,600 2026-04-21
Configurator MEDIUM 6.1
CVE-2026-34274

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Peopletools MEDIUM 6.6
CVE-2026-34277

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected ar…

Mitigation only
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2026-34269

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.…

Mitigation only
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Hcm Shared Components MEDIUM 5.4
CVE-2026-22019

Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version tha…

Mitigation only
Fix from $1,600 2026-04-21
Financial Services Analytical Applications Infrastructure HIGH 7.5
CVE-2026-22010

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,950 2026-04-21
Applications Dba HIGH 7.6
CVE-2026-22011

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.…

Fix: after 12.2.15
Fix from $1,950 2026-04-21
Life Sciences Empirica Signal HIGH 8.5
CVE-2026-21997

Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions t…

Fix: after 9.2.3
Fix from $1,950 2026-04-21
Frappe Hr MEDIUM 6.5
CVE-2026-40888

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role…

Fix: 15.58.1 / 16.4.1+
Fix from $1,600 2026-04-21
Frappe Hr MEDIUM 6.5
CVE-2026-40889

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthor…

Fix: 15.58.2 / 16.4.2+
Fix from $1,600 2026-04-21
Unclassified MEDIUM 6.0
CVE-2026-40874

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place…

Mitigation only
Fix from $1,600 2026-04-21
Unclassified HIGH 7.1
CVE-2026-40865

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document vie…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 8.6
CVE-2026-40866

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upl…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-40867

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.0
CVE-2026-40569

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connectio…

Patch available
Fix from $2,300 2026-04-21
Textpattern MEDIUM 6.5
CVE-2026-30452

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privil…

Mitigation only
Fix from $1,600 2026-04-21
Freescout CRITICAL 9.8
CVE-2026-40498

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …

Fix: 1.8.213+
Fix from $2,300 2026-04-21
Unclassified MEDIUM 5.3
CVE-2026-29644

XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) has improper gating of its dis…

Patch available
Fix from $1,600 2026-04-21
Dolibarr Erp\/crm HIGH 8.8
CVE-2026-31018

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input…

Fix: after 22.0.4
Fix from $1,950 2026-04-21
Neko HIGH 8.8
CVE-2026-39386

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…

Fix: 3.0.11 / 3.1.2+
Fix from $1,950 2026-04-21
Openclaude HIGH 8.4
CVE-2026-35570

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `b…

Fix: 0.5.1+
Fix from $1,950 2026-04-21
Nginx Ui HIGH 8.1
CVE-2026-33031

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously iss…

Fix: 2.3.4+
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6602

A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6596

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/b…

Mitigation only
Fix from $1,950 2026-04-20