Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Fastapiadmin HIGH 8.8
CVE-2026-2977

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/m…

Fix: after 2.2.0
Fix from $1,950 2026-02-23
Fastapiadmin HIGH 8.8
CVE-2026-2978

A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api…

Fix: after 2.2.0
Fix from $1,950 2026-02-23
Fastapiadmin MEDIUM 6.5
CVE-2026-2976

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v…

Fix: after 2.2.0
Fix from $1,600 2026-02-23
Fastapiadmin MEDIUM 5.3
CVE-2026-2975

A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/a…

Fix: after 2.2.0
Fix from $1,600 2026-02-23
Student Result Management System HIGH 7.3
CVE-2026-2938

A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/…

No fix yet
Fix from $1,950 2026-02-22
Funadmin CRITICAL 9.1
CVE-2026-2894

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo…

Fix: 7.1.0+
Fix from $2,300 2026-02-21
Erpnext CRITICAL 9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…

Fix: 15.98.1 / 16.6.1+
Fix from $2,300 2026-02-21
Foswiki MEDIUM 5.3
CVE-2026-2861

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipul…

Fix: 2.1.11+
Fix from $1,600 2026-02-21
Warehouse MEDIUM 6.3
CVE-2026-2852

A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSal…

Fix: after 2025-10-06
Fix from $1,600 2026-02-20
Warehouse MEDIUM 5.3
CVE-2026-2851

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/…

Fix: after 2025-10-06
Fix from $1,600 2026-02-20
Warehouse MEDIUM 6.5
CVE-2026-2850

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/de…

Fix: after 2025-10-06
Fix from $1,600 2026-02-20
Warehouse MEDIUM 6.3
CVE-2026-2849

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache…

Fix: after 2025-10-06
Fix from $1,600 2026-02-20
Unclassified CRITICAL 9.5
CVE-2026-21627

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain c…

Mitigation only
Fix from $2,300 2026-02-20
Learning MEDIUM 5.3
CVE-2026-26977

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized use…

Fix: 2.45.0+
Fix from $1,600 2026-02-20
Openclaw MEDIUM 6.5
CVE-2026-26328

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by se…

Fix: 2026.2.14+
Fix from $1,600 2026-02-20
Openclaw HIGH 7.2
CVE-2026-26325

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handle…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Teams HIGH 7.5
CVE-2026-21535

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-02-19
Gogs MEDIUM 6.5
CVE-2026-25229

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users…

Fix: 0.14.1+
Fix from $1,600 2026-02-19
Electronic Archives System CRITICAL 9.8
CVE-2026-2684

A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o…

Fix: after 3.2.210802
Fix from $2,300 2026-02-19
Visual Integrated Command And Dispatch Platform MEDIUM 6.5
CVE-2026-2669

A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the…

Fix: after 2026-02-06
Fix from $1,600 2026-02-18
Visual Integrated Command And Dispatch Platform MEDIUM 5.3
CVE-2026-2667

A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown func…

Fix: after 2026-02-06
Fix from $1,600 2026-02-18
Visual Integrated Command And Dispatch Platform HIGH 7.3
CVE-2026-2668

A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file…

Fix: after 2026-02-06
Fix from $1,950 2026-02-18
Unclassified MEDIUM 6.3
CVE-2026-2665

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file Sys…

Mitigation only
Fix from $1,600 2026-02-18
Mcms HIGH 7.2
CVE-2026-2666

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Tem…

No fix yet
Fix from $1,950 2026-02-18
Hospital Management System HIGH 8.8
CVE-2025-70064

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Adm…

No fix yet
Fix from $1,950 2026-02-18
Aruba Networking Private 5g Core HIGH 8.8
CVE-2026-23595

An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vul…

Fix: after 1.24.3.3
Fix from $1,950 2026-02-17
Unclassified HIGH 7.7
CVE-2026-2592

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and…

Mitigation only
Fix from $1,950 2026-02-17
Unclassified HIGH 7.3
CVE-2026-2549

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.…

Mitigation only
Fix from $1,950 2026-02-16
Unclassified CRITICAL 9.8
CVE-2026-2550

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-02-16
Lavalite HIGH 8.8
CVE-2025-70866

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the ad…

No fix yet
Fix from $1,950 2026-02-13