Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Wekan MEDIUM 5.3
CVE-2026-1964

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1963

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage…

Fix: 8.21+
Fix from $2,300 2026-02-05
Wekan CRITICAL 9.8
CVE-2026-1962

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp…

Fix: 8.21+
Fix from $2,300 2026-02-05
Pgadmin 4 MEDIUM 6.3
CVE-2026-1707

pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and perfo…

Mitigation only
Fix from $1,600 2026-02-05
Axigen Mail Server HIGH 8.1
CVE-2025-68721

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero pe…

Fix: 10.5.57 / 10.6.26+
Fix from $1,950 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1898

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1896

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig…

Fix: 8.21+
Fix from $1,600 2026-02-05
Wekan MEDIUM 6.3
CVE-2026-1895

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han…

Fix: 8.21+
Fix from $1,600 2026-02-04
Openslides CRITICAL 9.8
CVE-2026-25519

OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to v…

Fix: 4.2.29+
Fix from $2,300 2026-02-04
Eladmin MEDIUM 6.5
CVE-2025-70997

A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permiss…

Fix: after 2.7
Fix from $1,600 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1813

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp…

Fix: after 2.6.4
Fix from $2,300 2026-02-04
Open Eclass Platform MEDIUM 6.5
CVE-2026-24670

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulne…

Fix: 4.2+
Fix from $1,600 2026-02-03
Open Eclass Platform MEDIUM 6.5
CVE-2026-24668

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulne…

Fix: 4.2+
Fix from $1,600 2026-02-03
Pc Helpsoft Driver Updater HIGH 7.8
CVE-2025-60865

Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater…

No fix yet
Fix from $1,950 2026-02-03
Open Eclass Platform HIGH 8.8
CVE-2020-37116

GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 8.2
CVE-2026-1117

A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO …

Patch available
Fix from $1,950 2026-02-02
A8004t Firmware HIGH 7.2
CVE-2026-1742

A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cg…

Mitigation only
Fix from $1,950 2026-02-02
Trusttunnel MEDIUM 5.3
CVE-2026-24904

TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks…

Fix: 0.9.115+
Fix from $1,600 2026-01-29
Qr Menu CRITICAL 9.8
CVE-2025-7016

Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse. This issu…

Mitigation only
Fix from $2,300 2026-01-29
Premiercolor HIGH 7.8
CVE-2025-46691

Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with loca…

Mitigation only
Fix from $1,950 2026-01-28
Unclassified HIGH 8.8
CVE-2026-0844

The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient res…

Mitigation only
Fix from $1,950 2026-01-28
Openemr HIGH 8.8
CVE-2025-67645

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access…

Patch available
Fix from $1,950 2026-01-28
Dozzle CRITICAL 9.9
CVE-2026-24740

Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict…

Fix: 9.0.3+
Fix from $2,300 2026-01-27
Hono MEDIUM 5.3
CVE-2026-24473

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudf…

Fix: 4.11.7+
Fix from $1,600 2026-01-27
Springblade CRITICAL 9.9
CVE-2025-70982

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive …

Mitigation only
Fix from $2,300 2026-01-26
News Portal HIGH 7.2
CVE-2026-1424

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation lea…

No fix yet
Fix from $1,950 2026-01-26
Online Examination System CRITICAL 9.8
CVE-2026-1423

A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admi…

Mitigation only
Fix from $2,300 2026-01-26
777vr1 Firmware MEDIUM 6.1
CVE-2026-1411

A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This …

Fix: after 01.00.09_55
Fix from $1,600 2026-01-26
Phpmyfaq MEDIUM 6.5
CVE-2026-24420

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download…

Fix: 4.0.17+
Fix from $1,600 2026-01-24
Ruoyi HIGH 7.5
CVE-2025-70986

Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

No fix yet
Fix from $1,950 2026-01-23