Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified HIGH 7.1
CVE-2026-33398

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is …

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.4
CVE-2026-10284

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.4
CVE-2026-10285

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordU…

Mitigation only
Fix from $1,600 2026-06-01
Approval MEDIUM 6.5
CVE-2026-45275

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app t…

Fix: 2.7.2+
Fix from $1,600 2026-06-01
Android Xr HIGH 7.8
CVE-2026-0072

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local …

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10269

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardG…

Patch available
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-10272

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown f…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10236

A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 5.4
CVE-2026-10218

A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.g…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10212

A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. …

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10211

A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tool…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified CRITICAL 9.9
CVE-2026-47744

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 8.1
CVE-2026-47740

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were call…

Patch available
Fix from $1,950 2026-05-29
Avideo MEDIUM 5.3
CVE-2026-45620

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an e…

Fix: after 29.0
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.3
CVE-2026-45297

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_…

Mitigation only
Fix from $1,600 2026-05-28
Hono MEDIUM 6.5
CVE-2026-47673

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify tha…

Fix: 4.12.21+
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.5
CVE-2025-68712

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. A…

Mitigation only
Fix from $1,600 2026-05-27
Db2 HIGH 7.5
CVE-2026-6938

IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

Fix: after 12.1.4
Fix from $1,950 2026-05-27
macOS MEDIUM 5.5
CVE-2025-43289

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app m…

Fix: 14.8 / 15.7+
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-46620

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. Th…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9484

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStu…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9483

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing …

Mitigation only
Fix from $1,600 2026-05-25
Unclassified HIGH 8.1
CVE-2026-9397

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the componen…

Mitigation only
Fix from $1,950 2026-05-24
Unclassified MEDIUM 6.3
CVE-2026-9376

A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the com…

Mitigation only
Fix from $1,600 2026-05-24
Unisphere For Powermax Virtual Appliance HIGH 7.5
CVE-2022-34363

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application run…

Fix: 10.0.0.2+
Fix from $1,950 2026-05-22
Ofbiz MEDIUM 6.5
CVE-2026-45187

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade t…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Weknora MEDIUM 6.3
CVE-2026-8786

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i…

Fix: after 0.3.6
Fix from $1,600 2026-05-18
Unclassified MEDIUM 6.3
CVE-2026-8747

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of t…

Mitigation only
Fix from $1,600 2026-05-17
Open5gs MEDIUM 6.3
CVE-2026-8743

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the compon…

Fix: after 2.7.6
Fix from $1,600 2026-05-17
Open Webui MEDIUM 5.4
CVE-2026-45365

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter pa…

Fix: 0.8.11+
Fix from $1,600 2026-05-15