Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.5 CVE-2026-28865 An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, … Ipados 14.8.5 / 15.7.5+ Fix from $1,9502026-03-25 MEDIUM 5.5 CVE-2026-28845 An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected … macOS 26.4+ Fix from $1,6002026-03-25 MEDIUM 5.3 CVE-2026-28839 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able … macOS 14.8.5 / 15.7.5+ Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-33162 Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c… Craft Cms 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33680 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenti… Vikunja 2.2.2+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-33668 Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disable… Vikunja 2.2.1+ Fix from $1,9502026-03-24 HIGH 7.3 CVE-2026-4617 A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToke… Mitigation only Fix from $1,9502026-03-24 HIGH 8.1 CVE-2026-32300 Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi… Connect Cms 1.41.1 / 2.41.1+ Fix from $1,9502026-03-23 MEDIUM 5.3 CVE-2025-10731 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to S… Mitigation only Fix from $1,6002026-03-23 MEDIUM 6.5 CVE-2025-10736 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to u… Mitigation only Fix from $1,6002026-03-23 MEDIUM 6.3 CVE-2026-4548 A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file ac… Mitigation only Fix from $1,6002026-03-22 CRITICAL 9.1 CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of … Grpc 1.79.3+ Fix from $2,3002026-03-20 HIGH 8.1 CVE-2026-31836 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Checkmate after 3.5.1 Fix from $1,9502026-03-20 HIGH 8.1 CVE-2026-33125 Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer ro… Frigate 0.16.3+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-30702 The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa… Mitigation only Fix from $2,3002026-03-18 MEDIUM 6.5 CVE-2026-32692 An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit… Juju 3.6.19+ Fix from $1,6002026-03-18 HIGH 8.1 CVE-2026-21886 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "I… Opencti 6.9.1+ Fix from $1,9502026-03-17 MEDIUM 6.3 CVE-2026-4171 A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of t… Mitigation only Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-32704 SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticat… Siyuan 3.6.1+ Fix from $1,6002026-03-16 MEDIUM 6.3 CVE-2026-4013 A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown function of the file add_a… No fix yet Fix from $1,6002026-03-12 HIGH 8.8 CVE-2026-28806 Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update … Nerveshub 2.4.0+ Fix from $1,9502026-03-10 MEDIUM 5.0 CVE-2026-30959 OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a… Oneuptime 10.0.21+ Fix from $1,6002026-03-10 CRITICAL 9.9 CVE-2026-30956 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol… Oneuptime 10.0.21+ Fix from $2,3002026-03-10 MEDIUM 6.5 CVE-2026-30870 PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, c… Mitigation only Fix from $1,6002026-03-10 HIGH 7.5 CVE-2026-28431 Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a v… Misskey 2026.3.1+ Fix from $1,9502026-03-10 MEDIUM 5.3 CVE-2026-3817 A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the f… Patients Waiting Area Queue Management System No fix yet Fix from $1,6002026-03-09 HIGH 7.3 CVE-2026-3764 A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /supe… Client Database Management System No fix yet Fix from $1,9502026-03-08 MEDIUM 5.4 CVE-2026-3761 A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_use… Client Database Management System No fix yet Fix from $1,6002026-03-08 CRITICAL 9.8 CVE-2026-3762 A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_d… Client Database Management System Mitigation only Fix from $2,3002026-03-08 MEDIUM 6.3 CVE-2026-3737 A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the c… Pet Grooming Management Software No fix yet Fix from $1,6002026-03-08