Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 6.5
CVE-2025-30508

Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unpri…

Mitigation only
Fix from $1,600 2026-02-10
Fuxa CRITICAL 9.8
CVE-2026-25893

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Polarlearn HIGH 7.5
CVE-2026-25885

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can …

Patch available
Fix from $1,950 2026-02-09
Placipy CRITICAL 9.8
CVE-2026-25809

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the …

Mitigation only
Fix from $2,300 2026-02-09
Wukong Crm HIGH 8.8
CVE-2026-2141

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/ka…

Fix: after 11.3.3
Fix from $1,950 2026-02-08
Coco Annotator HIGH 8.1
CVE-2026-2109

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete…

Fix: after 0.11.1
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2107

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2106

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/upd…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2105

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/del…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2079

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2078

A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermis…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2077

A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Warehouse HIGH 8.8
CVE-2026-2076

A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function add…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Claude Code HIGH 7.5
CVE-2026-25724

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when acc…

Fix: 2.1.7+
Fix from $1,950 2026-02-06
I Educar HIGH 8.8
CVE-2026-2015

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the com…

Fix: after 2.10.0
Fix from $1,950 2026-02-06
Unclassified MEDIUM 5.3
CVE-2026-23623

Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.…

Mitigation only
Fix from $1,600 2026-02-06
Wekan MEDIUM 5.4
CVE-2026-1894

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe…

Fix: 8.21+
Fix from $1,600 2026-02-04
Wekan MEDIUM 5.0
CVE-2026-1892

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component …

Fix: 8.21+
Fix from $1,600 2026-02-04
Pet Grooming Management Software HIGH 8.8
CVE-2026-1702

A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/use…

No fix yet
Fix from $1,950 2026-01-30
Saleserp HIGH 8.8
CVE-2026-1597

A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint…

No fix yet
Fix from $1,950 2026-01-29
Hospital Management System HIGH 8.8
CVE-2026-1550

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /h…

No fix yet
Fix from $1,950 2026-01-28
Podman Desktop HIGH 7.1
CVE-2026-24835

Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prio…

Fix: 1.25.1+
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.9
CVE-2025-59100

The web interface offers a functionality to export the internal SQLite database. After executing the database export, an automatic download is starte…

Mitigation only
Fix from $1,600 2026-01-26
Entra Id CRITICAL 9.8
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-01-22
Solr HIGH 8.2
CVE-2026-22022

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access …

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Revive Adserver MEDIUM 6.5
CVE-2026-21641

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adse…

Fix: after 6.0.4
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.3
CVE-2025-14348

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to auth…

Mitigation only
Fix from $1,600 2026-01-20
Mineadmin HIGH 8.8
CVE-2026-1193

A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View…

No fix yet
Fix from $1,950 2026-01-19
News Portal HIGH 8.8
CVE-2026-1141

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the…

No fix yet
Fix from $1,950 2026-01-19
Publiccms HIGH 8.1
CVE-2026-1112

A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public…

Fix: after 5.202506.d
Fix from $1,950 2026-01-18