Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Open Webui MEDIUM 6.5
CVE-2026-45345

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's m…

Fix: 0.5.7+
Fix from $1,600 2026-05-15
Unclassified HIGH 7.2
CVE-2026-45371

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.6
CVE-2026-44504

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a …

Mitigation only
Fix from $1,950 2026-05-14
Tomcat CRITICAL 9.1
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Pocket Id HIGH 8.1
CVE-2026-43983

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken…

Fix: 2.6.0+
Fix from $1,950 2026-05-12
Vaultwarden HIGH 8.7
CVE-2026-43912

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_u…

Fix: 1.35.5+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-42875

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Na…

Mitigation only
Fix from $1,600 2026-05-11
Grav HIGH 8.1
CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o…

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8241

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of …

Mitigation only
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.5
CVE-2026-42202

nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{res…

Mitigation only
Fix from $1,600 2026-05-08
Teams MEDIUM 6.5
CVE-2026-33823

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-05-07
Unclassified CRITICAL 9.8
CVE-2026-30496

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated …

Mitigation only
Fix from $2,300 2026-05-07
Unclassified HIGH 8.8
CVE-2026-30495

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network w…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 6.3
CVE-2026-7782

A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Cli…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 5.3
CVE-2026-41572

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploa…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7713

A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token …

Patch available
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7709

A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_au…

Mitigation only
Fix from $1,600 2026-05-03
Unclassified MEDIUM 5.3
CVE-2026-7702

A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId…

No fix yet
Fix from $1,600 2026-05-03
Unclassified MEDIUM 6.5
CVE-2026-7681

A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $1,600 2026-05-03
Unclassified HIGH 7.3
CVE-2026-7644

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The man…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 5.4
CVE-2026-7631

A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Regist…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 5.3
CVE-2026-6449

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7602

A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the …

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7510

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark…

Patch available
Fix from $1,600 2026-04-30
Unclassified HIGH 7.3
CVE-2026-7505

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This man…

Patch available
Fix from $1,950 2026-04-30
Unclassified MEDIUM 5.4
CVE-2026-7502

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/…

Patch available
Fix from $1,600 2026-04-30
Unclassified HIGH 7.5
CVE-2026-2892

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the '…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified MEDIUM 5.6
CVE-2026-7292

A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAge…

Mitigation only
Fix from $1,600 2026-04-28
Minerva HIGH 8.8
CVE-2026-5781

An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user wi…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.4
CVE-2026-7145

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/Workspa…

Mitigation only
Fix from $1,600 2026-04-27