Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Parse Server MEDIUM 6.5
CVE-2026-30962

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the valida…

Fix: 8.6.19 / 9.5.2+
Fix from $1,600 2026-03-10
Parse Server CRITICAL 10.0
CVE-2026-30966

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Serv…

Fix: 8.6.20 / 9.5.2+
Fix from $2,300 2026-03-10
Vaadin MEDIUM 5.3
CVE-2026-2742

An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.…

Fix: 14.14.1 / 23.6.7+
Fix from $1,600 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-25176

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-24290

Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows Admin Center HIGH 7.8
CVE-2026-23660

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2.6.4+
Fix from $1,950 2026-03-10
Fortiswitchaxfixed MEDIUM 6.7
CVE-2026-22628

An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system comman…

Fix: 1.0.2+
Fix from $1,600 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-21262

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
Siyuan HIGH 7.1
CVE-2026-30926

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note …

Fix: 3.5.10+
Fix from $1,950 2026-03-10
Freshrss HIGH 7.5
CVE-2025-62166

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is …

Fix: 1.28.0+
Fix from $1,950 2026-03-09
W15e Firmware HIGH 7.5
CVE-2026-30140

An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/Route…

Mitigation only
Fix from $1,950 2026-03-09
Resort Reservation System HIGH 8.8
CVE-2026-3800

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?…

No fix yet
Fix from $1,950 2026-03-09
Video Surveillance System Firmware HIGH 8.8
CVE-2026-3797

A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o…

Mitigation only
Fix from $1,950 2026-03-09
Qax Internet Control Gateway HIGH 7.8
CVE-2026-3796

A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library…

Fix: after 2025-10-22
Fix from $1,950 2026-03-09
Bytedesk HIGH 8.8
CVE-2026-3748

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/…

Fix: 1.4.5.1+
Fix from $1,950 2026-03-08
Bytedesk HIGH 8.8
CVE-2026-3749

A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav…

Fix: 1.4.5.1+
Fix from $1,950 2026-03-08
Weknora HIGH 8.8
CVE-2026-30855

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass …

Fix: 0.3.2+
Fix from $1,950 2026-03-07
Weknora MEDIUM 6.5
CVE-2026-30859

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control…

Fix: 0.2.12+
Fix from $1,600 2026-03-07
Plane HIGH 7.5
CVE-2026-30244

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…

Fix: 1.2.2+
Fix from $1,950 2026-03-06
Ez Platform HIGH 7.5
CVE-2025-70363

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive…

Fix: after 2.5.32
Fix from $1,950 2026-03-06
Gokapi MEDIUM 5.0
CVE-2026-29060

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privi…

Fix: 2.2.3+
Fix from $1,600 2026-03-06
Gokapi MEDIUM 5.4
CVE-2026-29061

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerab…

Fix: 2.2.3+
Fix from $1,600 2026-03-06
Gokapi MEDIUM 6.4
CVE-2026-28682

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implement…

Fix: 2.2.3+
Fix from $1,600 2026-03-06
Chartbrew MEDIUM 6.5
CVE-2026-25877

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…

Fix: 4.8.1+
Fix from $1,600 2026-03-06
Filebrowser HIGH 8.1
CVE-2026-29188

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…

Fix: 2.61.1+
Fix from $1,950 2026-03-05
Frappe HIGH 7.1
CVE-2026-29077

Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user …

Fix: 14.100.0 / 15.98.0+
Fix from $1,950 2026-03-05
Graph Protocol Contracts HIGH 8.1
CVE-2026-28410

The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the to…

Fix: 3.0.0+
Fix from $1,950 2026-03-05
Ussd Gateway HIGH 8.1
CVE-2025-70614

OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing…

Mitigation only
Fix from $1,950 2026-03-05
Olivetin HIGH 7.5
CVE-2026-28790

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…

Fix: 3000.11.0+
Fix from $1,950 2026-03-05
Openproject MEDIUM 5.3
CVE-2026-27723

OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belongin…

Fix: 17.0.5 / 17.1.2+
Fix from $1,600 2026-03-05