Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.9 CVE-2025-70983 Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. Springblade Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.1 CVE-2025-70985 Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. Ruoyi No fix yet Fix from $2,3002026-01-23 HIGH 7.5 CVE-2025-69908 An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly acc… Omniapp No fix yet Fix from $1,9502026-01-23 HIGH 7.5 CVE-2025-69907 An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/G… Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.9 CVE-2026-24304 Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. Azure Resource Manager Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24306 Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. Azure Front Door No fix yet Fix from $2,3002026-01-22 MEDIUM 6.5 CVE-2026-20904 Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o… Gitea 1.25.4+ Fix from $1,6002026-01-22 CRITICAL 9.1 CVE-2026-20912 Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20897 Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L… Gitea 1.25.4+ Fix from $2,3002026-01-22 HIGH 7.5 CVE-2026-20736 Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able… Gitea 1.25.4+ Fix from $1,9502026-01-22 CRITICAL 9.1 CVE-2026-20750 Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab… Gitea 1.25.4+ Fix from $2,3002026-01-22 MEDIUM 6.5 CVE-2026-20883 Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still vi… Gitea 1.25.4+ Fix from $1,6002026-01-22 HIGH 7.4 CVE-2025-69822 An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi… Erica Smart Fan Firmware No fix yet Fix from $1,9502026-01-22 HIGH 7.4 CVE-2025-65098 Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential… Typebot 3.13.2+ Fix from $1,9502026-01-22 MEDIUM 5.3 CVE-2026-24055 Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates… Langfuse 3.147.0+ Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2026-24036 Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recr… Horilla Patch available Fix from $1,6002026-01-22 MEDIUM 6.4 CVE-2026-21982 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-21984 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,9502026-01-20 CRITICAL 10.0 CVE-2026-21962EPSS 43% Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy P… HTTP Server Patch available Fix from $2,3002026-01-20 MEDIUM 6.5 CVE-2026-21960 Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12… Applications Dba after 12.2.15 Fix from $1,6002026-01-20 MEDIUM 6.1 CVE-2026-21961 Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer, Employee Snap… Peoplesoft Enterprise Hcm Human Resources Mitigation only Fix from $1,6002026-01-20 CRITICAL 10.0 CVE-2026-21636 A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even … Node.js 25.3.0+ Fix from $2,3002026-01-20 HIGH 8.1 CVE-2025-14977 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure… Mitigation only Fix from $1,9502026-01-20 MEDIUM 5.3 CVE-2026-1196 A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulati… Mineadmin No fix yet Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-1194 A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in info… Mineadmin No fix yet Fix from $1,9502026-01-20 MEDIUM 5.3 CVE-2026-1170 A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file /graphql of the component Gra… Prime after 0.4.0 Fix from $1,6002026-01-19 CRITICAL 9.0 CVE-2026-1181 Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-… Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1152 A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code … Mpay after 1.2.4 Fix from $2,3002026-01-19 MEDIUM 6.3 CVE-2026-1126 A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the function uploadFile of the fi… Mitigation only Fix from $1,6002026-01-18 CRITICAL 9.8 CVE-2026-1107 A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av… Eyoucms Mitigation only Fix from $2,3002026-01-18