Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 6.3
CVE-2026-7142

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of t…

Patch available
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.3
CVE-2026-7109

A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API …

No fix yet
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7091

A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Manage…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7092

A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7093

A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /inv…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-6977

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask A…

Mitigation only
Fix from $1,950 2026-04-25
Unclassified MEDIUM 6.5
CVE-2025-67259

A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized cour…

Mitigation only
Fix from $1,600 2026-04-24
Weblogic Server MEDIUM 6.5
CVE-2026-34315

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …

Mitigation only
Fix from $1,600 2026-04-21
Financial Services Customer Screening HIGH 7.5
CVE-2026-34320

Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (component: User Interface). Th…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.3
CVE-2026-6634

A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component …

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6613

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of …

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6614

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_pr…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6612

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of t…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6609

A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This mani…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6584

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/contr…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6585

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6586

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/co…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6583

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superag…

Mitigation only
Fix from $1,600 2026-04-19
Unclassified MEDIUM 5.6
CVE-2026-6572

A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app…

Mitigation only
Fix from $1,600 2026-04-19
Unclassified MEDIUM 6.3
CVE-2026-6571

A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/co…

Mitigation only
Fix from $1,600 2026-04-19
Siyuan HIGH 8.1
CVE-2026-40259

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protect…

Fix: 3.6.4+
Fix from $1,950 2026-04-16
Free5gc HIGH 7.5
CVE-2026-40246

free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the handler for deleting Traffic Inf…

Fix: after 1.4.2
Fix from $1,950 2026-04-16
Free5gc HIGH 7.5
CVE-2026-40247

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for reading Traffic Infl…

Fix: after 4.2.1
Fix from $1,950 2026-04-16
Free5gc HIGH 7.5
CVE-2026-40248

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating…

Fix: after 4.2.1
Fix from $1,950 2026-04-16
Chamilo Lms MEDIUM 6.5
CVE-2026-34370

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Ref…

Fix: after 1.11.38
Fix from $1,600 2026-04-14
Windows Server 2012 HIGH 8.0
CVE-2026-27912

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Snipe It MEDIUM 6.5
CVE-2026-38533

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit perm…

No fix yet
Fix from $1,600 2026-04-14
Unclassified HIGH 7.3
CVE-2026-6105

A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/…

Mitigation only
Fix from $1,950 2026-04-11
Chartbrew HIGH 7.7
CVE-2026-32252

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cros…

Fix: 4.9.0+
Fix from $1,950 2026-04-10
Juju MEDIUM 6.5
CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API…

Fix: 2.9.57 / 3.6.21+
Fix from $1,600 2026-04-10