Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 6.3
CVE-2026-5999

A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulati…

Mitigation only
Fix from $1,600 2026-04-10
Unclassified HIGH 7.3
CVE-2026-5842

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the compo…

Mitigation only
Fix from $1,950 2026-04-09
Unclassified MEDIUM 5.7
CVE-2026-39901

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated t…

Mitigation only
Fix from $1,600 2026-04-08
Saleor MEDIUM 6.5
CVE-2026-35407

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found i…

Fix: 3.20.118 / 3.21.54+
Fix from $1,600 2026-04-08
Ci4ms HIGH 7.2
CVE-2026-39389

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.4.0+
Fix from $1,950 2026-04-08
Polarlearn HIGH 8.8
CVE-2026-35610

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in…

No fix yet
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5642

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown functio…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.1
CVE-2017-20238

Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows…

Mitigation only
Fix from $1,950 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Signal K Server CRITICAL 9.4
CVE-2026-33950

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…

Fix: 2.24.0+
Fix from $2,300 2026-04-02
Unclassified MEDIUM 5.3
CVE-2026-5326

A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_use…

Mitigation only
Fix from $1,600 2026-04-02
Mongoose HIGH 8.1
CVE-2026-5246

A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co…

Fix: 7.21+
Fix from $1,950 2026-04-02
Open Webui HIGH 7.7
CVE-2026-34222EPSS 5%

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access …

Fix: 0.8.11+
Fix from $1,950 2026-04-01
Chrome MEDIUM 6.5
CVE-2026-5283

Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML…

Fix: 146.0.7680.177+
Fix from $1,600 2026-04-01
Parse Server HIGH 7.5
CVE-2026-34784

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, f…

Fix: 8.6.71 / 9.7.1+
Fix from $1,950 2026-03-31
Discourse MEDIUM 5.3
CVE-2026-33074

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 5.4
CVE-2026-32615

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Flx HIGH 8.1
CVE-2026-4818

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage…

Fix: 4.1.0+
Fix from $1,950 2026-03-31
Unclassified MEDIUM 6.5
CVE-2026-1710

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Mitigation only
Fix from $1,600 2026-03-31
Scitokens Library MEDIUM 6.5
CVE-2026-32716

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using …

Fix: 1.9.6+
Fix from $1,600 2026-03-31
Basercms MEDIUM 5.3
CVE-2026-30878

baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form en…

Fix: 5.2.3+
Fix from $1,600 2026-03-31
Unclassified HIGH 8.0
CVE-2026-4248

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to…

Patch available
Fix from $1,950 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4990

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the compon…

Mitigation only
Fix from $1,950 2026-03-27
Linkace MEDIUM 6.5
CVE-2026-33954

LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed…

Fix: 2.5.3+
Fix from $1,600 2026-03-27
Xagent MEDIUM 6.5
CVE-2026-4958

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentSe…

No fix yet
Fix from $1,600 2026-03-27
Mytube HIGH 8.8
CVE-2026-33735

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/impor…

Fix: 1.8.69+
Fix from $1,950 2026-03-27
Openemr MEDIUM 6.5
CVE-2026-34056

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in Ope…

Fix: after 8.0.0.3
Fix from $1,600 2026-03-26
Openemr MEDIUM 5.4
CVE-2026-34051

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper a…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
macOS MEDIUM 5.5
CVE-2026-28881

A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

Fix: 26.4+
Fix from $1,600 2026-03-25