Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2025-30508 Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unpri… Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.8 CVE-2026-25893 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u… Fuxa 1.2.10+ Fix from $2,3002026-02-09 HIGH 7.5 CVE-2026-25885 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can … Polarlearn Patch available Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-25809 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the … Placipy Mitigation only Fix from $2,3002026-02-09 HIGH 8.8 CVE-2026-2141 A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/ka… Wukong Crm after 11.3.3 Fix from $1,9502026-02-08 HIGH 8.1 CVE-2026-2109 A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete… Coco Annotator after 0.11.1 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2107 A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2106 A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/upd… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2105 A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/del… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2079 A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2078 A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermis… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2077 A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 8.8 CVE-2026-2076 A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function add… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25724 Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when acc… Claude Code 2.1.7+ Fix from $1,9502026-02-06 HIGH 8.8 CVE-2026-2015 A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the com… I Educar after 2.10.0 Fix from $1,9502026-02-06 MEDIUM 5.3 CVE-2026-23623 Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.… Mitigation only Fix from $1,6002026-02-06 MEDIUM 5.4 CVE-2026-1894 A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Pe… Wekan 8.21+ Fix from $1,6002026-02-04 MEDIUM 5.0 CVE-2026-1892 A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component … Wekan 8.21+ Fix from $1,6002026-02-04 HIGH 8.8 CVE-2026-1702 A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/use… Pet Grooming Management Software No fix yet Fix from $1,9502026-01-30 HIGH 8.8 CVE-2026-1597 A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint… Saleserp No fix yet Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-1550 A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /h… Hospital Management System No fix yet Fix from $1,9502026-01-28 HIGH 7.1 CVE-2026-24835 Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prio… Podman Desktop 1.25.1+ Fix from $1,9502026-01-28 MEDIUM 5.9 CVE-2025-59100 The web interface offers a functionality to export the internal SQLite database. After executing the database export, an automatic download is starte… Mitigation only Fix from $1,6002026-01-26 CRITICAL 9.8 CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002026-01-22 HIGH 8.2 CVE-2026-22022 Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access … Solr 9.10.1+ Fix from $1,9502026-01-21 MEDIUM 6.5 CVE-2026-21641 HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adse… Revive Adserver after 6.0.4 Fix from $1,6002026-01-20 MEDIUM 5.3 CVE-2025-14348 The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to auth… Mitigation only Fix from $1,6002026-01-20 HIGH 8.8 CVE-2026-1193 A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View… Mineadmin No fix yet Fix from $1,9502026-01-19 HIGH 8.8 CVE-2026-1141 A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the… News Portal No fix yet Fix from $1,9502026-01-19 HIGH 8.1 CVE-2026-1112 A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public… Publiccms after 5.202506.d Fix from $1,9502026-01-18