Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Pet Grooming Management Software MEDIUM 6.3
CVE-2026-3738

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Finan…

No fix yet
Fix from $1,600 2026-03-08
Client Database Management System HIGH 7.3
CVE-2026-3734

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php…

No fix yet
Fix from $1,950 2026-03-08
Patients Waiting Area Queue Management System HIGH 8.8
CVE-2026-3724

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /che…

No fix yet
Fix from $1,950 2026-03-08
Unclassified MEDIUM 5.3
CVE-2026-3674

A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAppProvider of the component or…

Mitigation only
Fix from $1,600 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-3675

A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppReceiver of the component org.e…

Mitigation only
Fix from $1,600 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-3670

A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component com.dgen.alarm. Performing a m…

No fix yet
Fix from $1,600 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-3669

A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmService of the component com.dgen.…

Mitigation only
Fix from $1,600 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-3667

A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAppService of the component org…

Mitigation only
Fix from $1,600 2026-03-07
Wekan MEDIUM 6.5
CVE-2026-30847

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user doc…

Fix: 8.33+
Fix from $1,600 2026-03-06
Kimai MEDIUM 6.5
CVE-2026-28685

Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice …

Fix: 2.51.0+
Fix from $1,600 2026-03-06
Openclaw CRITICAL 9.4
CVE-2026-28448

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor…

Fix: 2026.2.1+
Fix from $2,300 2026-03-05
Rustdesk CRITICAL 9.8
CVE-2026-30793

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR…

Fix: after 1.4.5
Fix from $2,300 2026-03-05
Vaultwarden HIGH 8.3
CVE-2026-27803

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has…

Fix: 1.35.4+
Fix from $1,950 2026-03-04
Android HIGH 7.7
CVE-2026-0017

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local…

Mitigation only
Fix from $1,950 2026-03-02
Free Crm HIGH 8.8
CVE-2026-3265

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Se…

Fix: after 2025-09-21
Fix from $1,950 2026-02-26
Asp.net Core Inventory Order Management System HIGH 8.8
CVE-2026-3263

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown …

Fix: after 9.20250118
Fix from $1,950 2026-02-26
Unclassified MEDIUM 5.4
CVE-2026-2694

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check …

Mitigation only
Fix from $1,600 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-24890

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Sz Boot Parent MEDIUM 5.3
CVE-2026-3185

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the…

Fix: after 0.9.0
Fix from $1,600 2026-02-25
Funadmin MEDIUM 5.3
CVE-2026-2896

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the co…

Fix: 7.1.0+
Fix from $1,600 2026-02-22
Unclassified MEDIUM 6.3
CVE-2026-2860

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted …

Mitigation only
Fix from $1,600 2026-02-21
E Commerce HIGH 8.1
CVE-2025-15582

A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Mana…

No fix yet
Fix from $1,950 2026-02-20
Spip MEDIUM 6.5
CVE-2025-71242

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorizati…

Fix: 4.1.20 / 4.2.17+
Fix from $1,600 2026-02-19
Cyreneadmin MEDIUM 6.5
CVE-2026-2693

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCo…

Fix: after 1.3.0
Fix from $1,600 2026-02-19
Unclassified HIGH 8.8
CVE-2025-4521

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabil…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified MEDIUM 6.3
CVE-2026-2676

A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle o…

Mitigation only
Fix from $1,600 2026-02-18
Autogpt Platform HIGH 8.8
CVE-2026-26020

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.48+
Fix from $1,950 2026-02-12
macOS MEDIUM 5.5
CVE-2026-20666

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive …

Fix: 26.3+
Fix from $1,600 2026-02-11
macOS MEDIUM 5.5
CVE-2025-43403

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Cipace HIGH 7.5
CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files.…

Fix: 9.17+
Fix from $1,950 2026-02-11