Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified HIGH 7.3
CVE-2026-12204

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveInteg…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-12189

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a ma…

Mitigation only
Fix from $1,600 2026-06-14
Unclassified MEDIUM 5.3
CVE-2026-12190

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.ge…

No fix yet
Fix from $1,600 2026-06-14
Unclassified MEDIUM 5.3
CVE-2026-49397

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-44208

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint a…

Mitigation only
Fix from $1,600 2026-06-12
Ofbiz HIGH 8.8
CVE-2026-47342

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apa…

Fix: 24.09.07+
Fix from $1,950 2026-06-10
Sharepoint Server HIGH 8.0
CVE-2026-47298

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.5
CVE-2026-45503

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
.net HIGH 7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Powertoys HIGH 7.8
CVE-2026-42902

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

Fix: 0.99.1+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.3
CVE-2026-11619

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/c…

Patch available
Fix from $1,600 2026-06-09
Unclassified HIGH 8.1
CVE-2026-46484

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / author…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.4
CVE-2026-11533

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vul…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified HIGH 8.8
CVE-2026-46656

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the c…

Patch available
Fix from $1,950 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11521

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This a…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11519

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /P…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified MEDIUM 5.0
CVE-2026-11500

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authenticat…

Patch available
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11476

A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this iss…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified HIGH 7.3
CVE-2026-11462

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/St…

Patch available
Fix from $1,950 2026-06-07
Unclassified MEDIUM 6.3
CVE-2026-11461

A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state…

Mitigation only
Fix from $1,600 2026-06-07
Unclassified MEDIUM 6.3
CVE-2026-11439

A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the compon…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.3
CVE-2026-11440

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.3
CVE-2026-11441

A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the c…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.3
CVE-2026-11438

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. Th…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified CRITICAL 9.8
CVE-2026-10580

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all ve…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-11336

A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8e…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-10876

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This…

No fix yet
Fix from $1,600 2026-06-05
Exchange Online HIGH 7.5
CVE-2026-48579

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.1
CVE-2026-41522

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.3
CVE-2026-10693

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functio…

Mitigation only
Fix from $1,600 2026-06-03