Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.3 CVE-2026-5999 A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulati… Mitigation only Fix from $1,6002026-04-10 HIGH 7.3 CVE-2026-5842 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the compo… Mitigation only Fix from $1,9502026-04-09 MEDIUM 5.7 CVE-2026-39901 monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated t… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-35407 Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found i… Saleor 3.20.118 / 3.21.54+ Fix from $1,6002026-04-08 HIGH 7.2 CVE-2026-39389 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.4.0+ Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-35610 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in… Polarlearn No fix yet Fix from $1,9502026-04-07 HIGH 7.3 CVE-2026-5642 A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown functio… Mitigation only Fix from $1,9502026-04-06 HIGH 7.1 CVE-2017-20238 Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows… Mitigation only Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.4 CVE-2026-33950 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera… Signal K Server 2.24.0+ Fix from $2,3002026-04-02 MEDIUM 5.3 CVE-2026-5326 A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_use… Mitigation only Fix from $1,6002026-04-02 HIGH 8.1 CVE-2026-5246 A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co… Mongoose 7.21+ Fix from $1,9502026-04-02 HIGH 7.7 CVE-2026-34222EPSS 5% Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access … Open Webui 0.8.11+ Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2026-5283 Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML… Chrome 146.0.7680.177+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2026-34784 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, f… Parse Server 8.6.71 / 9.7.1+ Fix from $1,9502026-03-31 MEDIUM 5.3 CVE-2026-33074 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-32615 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 HIGH 8.1 CVE-2026-4818 In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage… Flx 4.1.0+ Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-1710 The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-32716 SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using … Scitokens Library 1.9.6+ Fix from $1,6002026-03-31 MEDIUM 5.3 CVE-2026-30878 baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form en… Basercms 5.2.3+ Fix from $1,6002026-03-31 HIGH 8.0 CVE-2026-4248 The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to… Patch available Fix from $1,9502026-03-27 HIGH 7.3 CVE-2026-4990 A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the compon… Mitigation only Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-33954 LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed… Linkace 2.5.3+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-4958 A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentSe… Xagent No fix yet Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-33735 MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/impor… Mytube 1.8.69+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-34056 OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in Ope… Openemr after 8.0.0.3 Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-34051 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper a… Openemr 8.0.0.3+ Fix from $1,6002026-03-26 MEDIUM 5.5 CVE-2026-28881 A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. macOS 26.4+ Fix from $1,6002026-03-25