Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
macOS MEDIUM 5.3
CVE-2026-28824

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28828

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-20697

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-20632

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.4. An app may b…

Fix: 26.4+
Fix from $1,600 2026-03-25
macOS HIGH 7.5
CVE-2026-20622

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Taho…

Fix: 15.7.4 / 26.3+
Fix from $1,950 2026-03-25
Ipados MEDIUM 6.8
CVE-2025-43534

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user w…

Fix: 18.7.7 / 26.2+
Fix from $1,600 2026-03-25
Vikunja HIGH 8.1
CVE-2026-33316

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user…

Fix: 2.2.0+
Fix from $1,950 2026-03-24
Langflow HIGH 7.5
CVE-2026-33484EPSS 6%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…

Fix: 1.9.0+
Fix from $1,950 2026-03-24
Langflow CRITICAL 9.9
CVE-2026-33309EPSS 11%

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…

Fix: 1.9.0+
Fix from $2,300 2026-03-24
Connect Cms HIGH 7.5
CVE-2026-32299

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…

Fix: 1.41.1 / 2.41.1+
Fix from $1,950 2026-03-23
Unclassified CRITICAL 9.0
CVE-2026-0898

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Micro…

Mitigation only
Fix from $2,300 2026-03-23
Avideo CRITICAL 10.0
CVE-2026-33478EPSS 13%

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…

Fix: after 26.0
Fix from $2,300 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4586

A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4536

A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulati…

Mitigation only
Fix from $1,950 2026-03-22
Unclassified MEDIUM 6.3
CVE-2026-4514

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserCon…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.3
CVE-2026-4505

A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages…

Mitigation only
Fix from $1,600 2026-03-20
Chall Manager CRITICAL 9.9
CVE-2026-32768

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPo…

Fix: 0.6.5+
Fix from $2,300 2026-03-20
Siyuan MEDIUM 6.5
CVE-2026-32938

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed …

Fix: 3.6.1+
Fix from $1,600 2026-03-20
Free5gc HIGH 7.5
CVE-2026-33062

free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Ser…

Fix: 1.4.2+
Fix from $1,950 2026-03-20
Fullchain CRITICAL 9.8
CVE-2026-32769

Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-written NetworkPolicy, a malici…

Fix: 0.1.1+
Fix from $2,300 2026-03-20
Filebrowser CRITICAL 9.8
CVE-2026-32760

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions …

Fix: 2.62.0+
Fix from $2,300 2026-03-20
Filebrowser MEDIUM 6.5
CVE-2026-32761

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…

Fix: 2.62.0+
Fix from $1,600 2026-03-20
Freescout HIGH 8.1
CVE-2026-32752

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method con…

Fix: 1.8.209+
Fix from $1,950 2026-03-19
Openclaw CRITICAL 9.0
CVE-2026-32038

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network…

Fix: 2026.2.24+
Fix from $2,300 2026-03-19
Romeo CRITICAL 10.0
CVE-2026-32737

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…

Fix: 0.2.1+
Fix from $2,300 2026-03-18
Juju HIGH 8.8
CVE-2026-32693

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th…

Fix: 3.6.19+
Fix from $1,950 2026-03-18
Librechat HIGH 8.0
CVE-2025-41258

LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of…

No fix yet
Fix from $1,950 2026-03-18
Kube Router HIGH 7.1
CVE-2026-32254

Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or load…

Fix: 2.8.0+
Fix from $1,950 2026-03-18
Okit CRITICAL 9.8
CVE-2026-21994

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop).…

Mitigation only
Fix from $2,300 2026-03-17
Unclassified HIGH 8.1
CVE-2026-30707

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails AS…

Mitigation only
Fix from $1,950 2026-03-17