Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.2 CVE-2026-41641 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQ… Nocobase 2.0.39+ Fix from $1,9502026-05-07 MEDIUM 5.3 CVE-2026-8033 A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ … Mitigation only Fix from $1,6002026-05-06 HIGH 7.7 CVE-2026-20167 A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv… Iot Field Network Director 5.0.0-117+ Fix from $1,9502026-05-06 MEDIUM 5.3 CVE-2026-8026 A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv… Flowise after 3.0.12 Fix from $1,6002026-05-06 HIGH 7.5 CVE-2024-52911 Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14. No fix yet Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-42222 Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init… Nginx Ui Mitigation only Fix from $2,3002026-05-04 HIGH 8.1 CVE-2025-67796 IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. T… Mitigation only Fix from $1,9502026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 HIGH 7.3 CVE-2026-7733 A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7732 A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.ph… Mitigation only Fix from $1,6002026-05-04 HIGH 7.3 CVE-2026-7711 A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wra… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7696 A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function … Mitigation only Fix from $1,6002026-05-03 MEDIUM 5.3 CVE-2026-7686 A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium… Mitigation only Fix from $1,6002026-05-03 HIGH 7.8 CVE-2026-37526 AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config,… Automotive Grade Linux after 17.1.12 Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-2311 IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali… I Mitigation only Fix from $2,3002026-04-30 MEDIUM 6.5 CVE-2026-40603 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char… Mitigation only Fix from $1,6002026-04-30 HIGH 8.1 CVE-2026-40904 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char… Mitigation only Fix from $1,9502026-04-30 HIGH 7.5 CVE-2026-40595 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char… Mitigation only Fix from $1,9502026-04-30 HIGH 7.3 CVE-2026-7468 A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/… Mitigation only Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-5141 Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research… Mitigation only Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-5779 An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. T… Minerva Mitigation only Fix from $1,9502026-04-28 HIGH 8.1 CVE-2026-5780 An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vul… Minerva Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.9 CVE-2026-40966 In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and c… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7107 A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This… Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7044 A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulati… Mitigation only Fix from $1,6002026-04-26 MEDIUM 6.3 CVE-2026-7043 A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. T… Mitigation only Fix from $1,6002026-04-26 MEDIUM 6.5 CVE-2025-67259 A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized cour… Mitigation only Fix from $1,6002026-04-24 HIGH 8.8 CVE-2026-33318 Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se… Actual 26.4.0+ Fix from $1,9502026-04-24 CRITICAL 9.6 CVE-2026-24303 Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center No fix yet Fix from $2,3002026-04-23 HIGH 8.8 CVE-2026-41277 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the Docum… Flowise 3.1.0+ Fix from $1,9502026-04-23