Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.3 CVE-2026-1964 A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. Thi… Wekan 8.21+ Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2026-1963 A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage… Wekan 8.21+ Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-1962 A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp… Wekan 8.21+ Fix from $2,3002026-02-05 MEDIUM 6.3 CVE-2026-1707 pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and perfo… Pgadmin 4 Mitigation only Fix from $1,6002026-02-05 HIGH 8.1 CVE-2025-68721 Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero pe… Axigen Mail Server 10.5.57 / 10.6.26+ Fix from $1,9502026-02-05 MEDIUM 6.3 CVE-2026-1898 A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component … Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 6.3 CVE-2026-1896 A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/mig… Wekan 8.21+ Fix from $1,6002026-02-05 MEDIUM 6.3 CVE-2026-1895 A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Han… Wekan 8.21+ Fix from $1,6002026-02-04 CRITICAL 9.8 CVE-2026-25519 OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to v… Openslides 4.2.29+ Fix from $2,3002026-02-04 MEDIUM 6.5 CVE-2025-70997 A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permiss… Eladmin after 2.7 Fix from $1,6002026-02-04 CRITICAL 9.8 CVE-2026-1813 A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp… Bolo Solo after 2.6.4 Fix from $2,3002026-02-04 MEDIUM 6.5 CVE-2026-24670 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulne… Open Eclass Platform 4.2+ Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24668 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulne… Open Eclass Platform 4.2+ Fix from $1,6002026-02-03 HIGH 7.8 CVE-2025-60865 Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater… Pc Helpsoft Driver Updater No fix yet Fix from $1,9502026-02-03 HIGH 8.8 CVE-2020-37116 GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access… Open Eclass Platform No fix yet Fix from $1,9502026-02-03 HIGH 8.2 CVE-2026-1117 A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO … Patch available Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-1742 A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cg… A8004t Firmware Mitigation only Fix from $1,9502026-02-02 MEDIUM 5.3 CVE-2026-24904 TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks… Trusttunnel 0.9.115+ Fix from $1,6002026-01-29 CRITICAL 9.8 CVE-2025-7016 Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse. This issu… Qr Menu Mitigation only Fix from $2,3002026-01-29 HIGH 7.8 CVE-2025-46691 Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with loca… Premiercolor Mitigation only Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-0844 The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient res… Mitigation only Fix from $1,9502026-01-28 HIGH 8.8 CVE-2025-67645 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access… Openemr Patch available Fix from $1,9502026-01-28 CRITICAL 9.9 CVE-2026-24740 Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict… Dozzle 9.0.3+ Fix from $2,3002026-01-27 MEDIUM 5.3 CVE-2026-24473 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudf… Hono 4.11.7+ Fix from $1,6002026-01-27 CRITICAL 9.9 CVE-2025-70982 Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive … Springblade Mitigation only Fix from $2,3002026-01-26 HIGH 7.2 CVE-2026-1424 A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation lea… News Portal No fix yet Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2026-1423 A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admi… Online Examination System Mitigation only Fix from $2,3002026-01-26 MEDIUM 6.1 CVE-2026-1411 A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This … 777vr1 Firmware after 01.00.09_55 Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-24420 phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download… Phpmyfaq 4.0.17+ Fix from $1,6002026-01-24 HIGH 7.5 CVE-2025-70986 Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data. Ruoyi No fix yet Fix from $1,9502026-01-23