Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.8 CVE-2026-58631 Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49170 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-15622 A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace… Patch available Fix from $1,6002026-07-14 MEDIUM 5.6 CVE-2026-15516 A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php … Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15509 A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulati… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15510 A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in im… Mitigation only Fix from $1,6002026-07-12 HIGH 8.1 CVE-2026-56313 Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrator… Mitigation only Fix from $1,9502026-07-12 MEDIUM 6.3 CVE-2026-15499 A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/… Mitigation only Fix from $1,6002026-07-12 HIGH 8.3 CVE-2026-56241 Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and… Mitigation only Fix from $1,9502026-07-12 MEDIUM 6.3 CVE-2026-15473 A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAc… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15376 A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15373 A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15374 A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the componen… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15318 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqt… Mitigation only Fix from $1,6002026-07-10 HIGH 7.1 CVE-2026-55212 Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint PO… Patch available Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15191 A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Re… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-58251 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica… Nats Server 2.11.16 / 2.12.7+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-58252 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica… Nats Server 2.11.16 / 2.12.7+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-56293 Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications b… Mitigation only Fix from $1,6002026-07-08 HIGH 8.1 CVE-2026-56246 Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inhe… Mitigation only Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-55428 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tail… Coder 2.29.17 / 2.32.7+ Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-55077 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT… Coder 2.29.17 / 2.32.7+ Fix from $1,9502026-07-07 CRITICAL 9.9 CVE-2026-34048 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots… Patch available Fix from $2,3002026-07-07 MEDIUM 5.5 CVE-2026-44362 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone… Op Tee after 4.10.0 Fix from $1,6002026-07-06 HIGH 7.3 CVE-2026-14778 A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the … Mitigation only Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-14753 A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP… Mitigation only Fix from $1,9502026-07-05 MEDIUM 6.3 CVE-2026-14716 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file i… Mitigation only Fix from $1,6002026-07-05 MEDIUM 5.4 CVE-2026-14693 A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_orde… Mitigation only Fix from $1,6002026-07-05 HIGH 7.3 CVE-2026-14690 A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file … No fix yet Fix from $1,9502026-07-05 HIGH 8.9 CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass Patch available Fix from $1,9502026-07-03