Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2026-2977 A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/m… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23 HIGH 8.8 CVE-2026-2978 A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23 MEDIUM 6.5 CVE-2026-2976 A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v… Fastapiadmin after 2.2.0 Fix from $1,6002026-02-23 MEDIUM 5.3 CVE-2026-2975 A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/a… Fastapiadmin after 2.2.0 Fix from $1,6002026-02-23 HIGH 7.3 CVE-2026-2938 A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/… Student Result Management System No fix yet Fix from $1,9502026-02-22 CRITICAL 9.1 CVE-2026-2894 A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo… Funadmin 7.1.0+ Fix from $2,3002026-02-21 CRITICAL 9.1 CVE-2026-27471 ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack… Erpnext 15.98.1 / 16.6.1+ Fix from $2,3002026-02-21 MEDIUM 5.3 CVE-2026-2861 A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipul… Foswiki 2.1.11+ Fix from $1,6002026-02-21 MEDIUM 6.3 CVE-2026-2852 A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSal… Warehouse after 2025-10-06 Fix from $1,6002026-02-20 MEDIUM 5.3 CVE-2026-2851 A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/… Warehouse after 2025-10-06 Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-2850 A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/de… Warehouse after 2025-10-06 Fix from $1,6002026-02-20 MEDIUM 6.3 CVE-2026-2849 A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache… Warehouse after 2025-10-06 Fix from $1,6002026-02-20 CRITICAL 9.5 CVE-2026-21627 The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain c… Mitigation only Fix from $2,3002026-02-20 MEDIUM 5.3 CVE-2026-26977 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized use… Learning 2.45.0+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26328 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by se… Openclaw 2026.2.14+ Fix from $1,6002026-02-20 HIGH 7.2 CVE-2026-26325 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handle… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-21535 Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. Teams Mitigation only Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2026-25229 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users… Gogs 0.14.1+ Fix from $1,6002026-02-19 CRITICAL 9.8 CVE-2026-2684 A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o… Electronic Archives System after 3.2.210802 Fix from $2,3002026-02-19 MEDIUM 6.5 CVE-2026-2669 A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the… Visual Integrated Command And Dispatch Platform after 2026-02-06 Fix from $1,6002026-02-18 MEDIUM 5.3 CVE-2026-2667 A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown func… Visual Integrated Command And Dispatch Platform after 2026-02-06 Fix from $1,6002026-02-18 HIGH 7.3 CVE-2026-2668 A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file… Visual Integrated Command And Dispatch Platform after 2026-02-06 Fix from $1,9502026-02-18 MEDIUM 6.3 CVE-2026-2665 A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file Sys… Mitigation only Fix from $1,6002026-02-18 HIGH 7.2 CVE-2026-2666 A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Tem… Mcms No fix yet Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-70064 PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Adm… Hospital Management System No fix yet Fix from $1,9502026-02-18 HIGH 8.8 CVE-2026-23595 An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vul… Aruba Networking Private 5g Core after 1.24.3.3 Fix from $1,9502026-02-17 HIGH 7.7 CVE-2026-2592 The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and… Mitigation only Fix from $1,9502026-02-17 HIGH 7.3 CVE-2026-2549 A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.… Mitigation only Fix from $1,9502026-02-16 CRITICAL 9.8 CVE-2026-2550 A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul… Mitigation only Fix from $2,3002026-02-16 HIGH 8.8 CVE-2025-70866 LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the ad… Lavalite No fix yet Fix from $1,9502026-02-13