Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.6 CVE-2026-60886 Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte… Work In Process after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-60844 Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are aff… Customer Support Mitigation only Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-60842 Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12… Knowledge Management after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-60152 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affect… Peoplesoft Enterprise Peopletools No fix yet Fix from $1,6002026-07-21 MEDIUM 5.6 CVE-2026-47053 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas… Vm Virtualbox No fix yet Fix from $1,6002026-07-21 CRITICAL 9.1 CVE-2026-28312 SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe… Serv U 2026.3+ Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-34239 Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is p… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-32806 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 8.1 CVE-2026-32821 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-27823 A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-32807 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.3 CVE-2026-16217 A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file d… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16214 A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the compon… No fix yet Fix from $1,6002026-07-19 HIGH 7.3 CVE-2026-16200 A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of t… No fix yet Fix from $1,9502026-07-19 MEDIUM 6.3 CVE-2026-16199 A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/cr… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16195 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/w… No fix yet Fix from $1,6002026-07-18 HIGH 7.3 CVE-2026-16126 A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm… No fix yet Fix from $1,9502026-07-18 MEDIUM 6.3 CVE-2026-16121 A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.g… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16119 A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.5 CVE-2024-58367 SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to… Surrealdb 2.0.4+ Fix from $1,6002026-07-18 MEDIUM 5.4 CVE-2026-61718 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware autho… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.3 CVE-2026-15909 A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil… No fix yet Fix from $1,6002026-07-16 HIGH 7.1 CVE-2026-53515 Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register… Better Auth\/sso 1.6.11+ Fix from $1,9502026-07-15 HIGH 7.6 CVE-2026-45337 Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authent… Better Auth 1.6.11+ Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-49997 SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb… Mitigation only Fix from $1,6002026-07-15 HIGH 7.8 CVE-2026-58540 Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-58277 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server Mitigation only Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-54121 Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50344 Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50346 Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14