Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Work In Process HIGH 7.6
CVE-2026-60886

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte…

Fix: after 12.2.15
Fix from $1,950 2026-07-21
Customer Support HIGH 8.1
CVE-2026-60844

Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are aff…

Mitigation only
Fix from $1,950 2026-07-21
Knowledge Management MEDIUM 6.1
CVE-2026-60842

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Peoplesoft Enterprise Peopletools MEDIUM 5.4
CVE-2026-60152

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affect…

No fix yet
Fix from $1,600 2026-07-21
Vm Virtualbox MEDIUM 5.6
CVE-2026-47053

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas…

No fix yet
Fix from $1,600 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Unclassified HIGH 7.5
CVE-2026-34239

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is p…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32806

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.1
CVE-2026-32821

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-27823

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32807

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16217

A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file d…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16214

A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the compon…

No fix yet
Fix from $1,600 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16200

A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of t…

No fix yet
Fix from $1,950 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16199

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/cr…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16195

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/w…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 7.3
CVE-2026-16126

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm…

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16121

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.g…

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16119

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval…

No fix yet
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58367

SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to…

Fix: 2.0.4+
Fix from $1,600 2026-07-18
Unclassified MEDIUM 5.4
CVE-2026-61718

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware autho…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.3
CVE-2026-15909

A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil…

No fix yet
Fix from $1,600 2026-07-16
Better Auth\/sso HIGH 7.1
CVE-2026-53515

Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Better Auth HIGH 7.6
CVE-2026-45337

Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authent…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-49997

SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb…

Mitigation only
Fix from $1,600 2026-07-15
Windows 10 1607 HIGH 7.8
CVE-2026-58540

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Sharepoint Server HIGH 8.8
CVE-2026-58277

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50344

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50346

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14