Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Ipados HIGH 7.5
CVE-2026-28865

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, …

Fix: 14.8.5 / 15.7.5+
Fix from $1,950 2026-03-25
macOS MEDIUM 5.5
CVE-2026-28845

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected …

Fix: 26.4+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28839

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able …

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Craft Cms MEDIUM 6.5
CVE-2026-33162

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c…

Fix: 5.9.14+
Fix from $1,600 2026-03-24
Vikunja MEDIUM 6.5
CVE-2026-33680

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenti…

Fix: 2.2.2+
Fix from $1,600 2026-03-24
Vikunja HIGH 8.1
CVE-2026-33668

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disable…

Fix: 2.2.1+
Fix from $1,950 2026-03-24
Unclassified HIGH 7.3
CVE-2026-4617

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToke…

Mitigation only
Fix from $1,950 2026-03-24
Connect Cms HIGH 8.1
CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…

Fix: 1.41.1 / 2.41.1+
Fix from $1,950 2026-03-23
Unclassified MEDIUM 5.3
CVE-2025-10731

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to S…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.5
CVE-2025-10736

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to u…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4548

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file ac…

Mitigation only
Fix from $1,600 2026-03-22
Grpc CRITICAL 9.1
CVE-2026-33186

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of …

Fix: 1.79.3+
Fix from $2,300 2026-03-20
Checkmate HIGH 8.1
CVE-2026-31836

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with …

Fix: after 3.5.1
Fix from $1,950 2026-03-20
Frigate HIGH 8.1
CVE-2026-33125

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer ro…

Fix: 0.16.3+
Fix from $1,950 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-30702

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa…

Mitigation only
Fix from $2,300 2026-03-18
Juju MEDIUM 6.5
CVE-2026-32692

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit…

Fix: 3.6.19+
Fix from $1,600 2026-03-18
Opencti HIGH 8.1
CVE-2026-21886

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "I…

Fix: 6.9.1+
Fix from $1,950 2026-03-17
Unclassified MEDIUM 6.3
CVE-2026-4171

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $1,600 2026-03-16
Siyuan MEDIUM 6.5
CVE-2026-32704

SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticat…

Fix: 3.6.1+
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4013

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown function of the file add_a…

No fix yet
Fix from $1,600 2026-03-12
Nerveshub HIGH 8.8
CVE-2026-28806

Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update …

Fix: 2.4.0+
Fix from $1,950 2026-03-10
Oneuptime MEDIUM 5.0
CVE-2026-30959

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a…

Fix: 10.0.21+
Fix from $1,600 2026-03-10
Oneuptime CRITICAL 9.9
CVE-2026-30956

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol…

Fix: 10.0.21+
Fix from $2,300 2026-03-10
Unclassified MEDIUM 6.5
CVE-2026-30870

PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, c…

Mitigation only
Fix from $1,600 2026-03-10
Misskey HIGH 7.5
CVE-2026-28431

Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a v…

Fix: 2026.3.1+
Fix from $1,950 2026-03-10
Patients Waiting Area Queue Management System MEDIUM 5.3
CVE-2026-3817

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the f…

No fix yet
Fix from $1,600 2026-03-09
Client Database Management System HIGH 7.3
CVE-2026-3764

A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /supe…

No fix yet
Fix from $1,950 2026-03-08
Client Database Management System MEDIUM 5.4
CVE-2026-3761

A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_use…

No fix yet
Fix from $1,600 2026-03-08
Client Database Management System CRITICAL 9.8
CVE-2026-3762

A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_d…

Mitigation only
Fix from $2,300 2026-03-08
Pet Grooming Management Software MEDIUM 6.3
CVE-2026-3737

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the c…

No fix yet
Fix from $1,600 2026-03-08