Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Springblade CRITICAL 9.9
CVE-2025-70983

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

Mitigation only
Fix from $2,300 2026-01-23
Ruoyi CRITICAL 9.1
CVE-2025-70985

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

No fix yet
Fix from $2,300 2026-01-23
Omniapp HIGH 7.5
CVE-2025-69908

An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly acc…

No fix yet
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2025-69907

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/G…

Mitigation only
Fix from $1,950 2026-01-23
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea HIGH 7.5
CVE-2026-20736

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able…

Fix: 1.25.4+
Fix from $1,950 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20883

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still vi…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Erica Smart Fan Firmware HIGH 7.4
CVE-2025-69822

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi…

No fix yet
Fix from $1,950 2026-01-22
Typebot HIGH 7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential…

Fix: 3.13.2+
Fix from $1,950 2026-01-22
Langfuse MEDIUM 5.3
CVE-2026-24055

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates…

Fix: 3.147.0+
Fix from $1,600 2026-01-22
Horilla MEDIUM 5.3
CVE-2026-24036

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recr…

Patch available
Fix from $1,600 2026-01-22
Vm Virtualbox MEDIUM 6.4
CVE-2026-21982

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,600 2026-01-20
Vm Virtualbox HIGH 7.5
CVE-2026-21984

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,950 2026-01-20
HTTP Server CRITICAL 10.0
CVE-2026-21962EPSS 43%

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy P…

Patch available
Fix from $2,300 2026-01-20
Applications Dba MEDIUM 6.5
CVE-2026-21960

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,600 2026-01-20
Peoplesoft Enterprise Hcm Human Resources MEDIUM 6.1
CVE-2026-21961

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer, Employee Snap…

Mitigation only
Fix from $1,600 2026-01-20
Node.js CRITICAL 10.0
CVE-2026-21636

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …

Fix: 25.3.0+
Fix from $2,300 2026-01-20
Unclassified HIGH 8.1
CVE-2025-14977

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure…

Mitigation only
Fix from $1,950 2026-01-20
Mineadmin MEDIUM 5.3
CVE-2026-1196

A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulati…

No fix yet
Fix from $1,600 2026-01-20
Mineadmin HIGH 7.5
CVE-2026-1194

A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in info…

No fix yet
Fix from $1,950 2026-01-20
Prime MEDIUM 5.3
CVE-2026-1170

A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file /graphql of the component Gra…

Fix: after 0.4.0
Fix from $1,600 2026-01-19
Unclassified CRITICAL 9.0
CVE-2026-1181

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-…

Mitigation only
Fix from $2,300 2026-01-19
Mpay CRITICAL 9.8
CVE-2026-1152

A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code …

Fix: after 1.2.4
Fix from $2,300 2026-01-19
Unclassified MEDIUM 6.3
CVE-2026-1126

A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the function uploadFile of the fi…

Mitigation only
Fix from $1,600 2026-01-18
Eyoucms CRITICAL 9.8
CVE-2026-1107

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…

Mitigation only
Fix from $2,300 2026-01-18