Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.2 CVE-2026-34292 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.9 CVE-2026-34294 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported v… Identity Manager Connector Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-34295 Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affec… Peoplesoft Enterprise Scm Purchasing Mitigation only Fix from $1,6002026-04-21 CRITICAL 9.1 CVE-2026-34287 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 HIGH 8.7 CVE-2026-34291 Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 a… HTTP Server Mitigation only Fix from $1,9502026-04-21 MEDIUM 6.1 CVE-2026-34283 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected… Identity Manager Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-34284 Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versio… Business Process Management Suite Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-34274 Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12… Configurator after 12.2.15 Fix from $1,6002026-04-21 MEDIUM 6.6 CVE-2026-34277 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected ar… Peoplesoft Enterprise Peopletools Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-34269 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.… Peoplesoft Enterprise Peopletools Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-22019 Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version tha… Peoplesoft Enterprise Hcm Shared Components Mitigation only Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-22010 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,9502026-04-21 HIGH 7.6 CVE-2026-22011 Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.… Applications Dba after 12.2.15 Fix from $1,9502026-04-21 HIGH 8.5 CVE-2026-21997 Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions t… Life Sciences Empirica Signal after 9.2.3 Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-40888 Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role… Frappe Hr 15.58.1 / 16.4.1+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-40889 Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthor… Frappe Hr 15.58.2 / 16.4.2+ Fix from $1,6002026-04-21 MEDIUM 6.0 CVE-2026-40874 mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place… Mitigation only Fix from $1,6002026-04-21 HIGH 7.1 CVE-2026-40865 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document vie… Mitigation only Fix from $1,9502026-04-21 HIGH 8.6 CVE-2026-40866 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upl… Mitigation only Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-40867 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment… Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.0 CVE-2026-40569 FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connectio… Patch available Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-30452 Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privil… Textpattern Mitigation only Fix from $1,6002026-04-21 CRITICAL 9.8 CVE-2026-40498 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system … Freescout 1.8.213+ Fix from $2,3002026-04-21 MEDIUM 5.3 CVE-2026-29644 XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) has improper gating of its dis… Patch available Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-31018 In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input… Dolibarr Erp\/crm after 22.0.4 Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-39386 Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat… Neko 3.0.11 / 3.1.2+ Fix from $1,9502026-04-21 HIGH 8.4 CVE-2026-35570 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `b… Openclaude 0.5.1+ Fix from $1,9502026-04-21 HIGH 8.1 CVE-2026-33031 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously iss… Nginx Ui 2.3.4+ Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6602 A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6596 A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/b… Mitigation only Fix from $1,9502026-04-20