Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.3 CVE-2026-12204 A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveInteg… Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-12189 A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a ma… Mitigation only Fix from $1,6002026-06-14 MEDIUM 5.3 CVE-2026-12190 A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.ge… No fix yet Fix from $1,6002026-06-14 MEDIUM 5.3 CVE-2026-49397 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private … Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-44208 Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint a… Mitigation only Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-47342 A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apa… Ofbiz 24.09.07+ Fix from $1,9502026-06-10 HIGH 8.0 CVE-2026-47298 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-45503 Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. Exchange Server 15.02.2562.043+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-45490 Improper authorization in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-42902 Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. Powertoys 0.99.1+ Fix from $1,9502026-06-09 MEDIUM 6.3 CVE-2026-11619 A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/c… Patch available Fix from $1,6002026-06-09 HIGH 8.1 CVE-2026-46484 Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / author… Mitigation only Fix from $1,9502026-06-08 MEDIUM 5.4 CVE-2026-11533 A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vul… Mitigation only Fix from $1,6002026-06-08 HIGH 8.8 CVE-2026-46656 Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the c… Patch available Fix from $1,9502026-06-08 MEDIUM 6.3 CVE-2026-11521 A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This a… Mitigation only Fix from $1,6002026-06-08 MEDIUM 6.3 CVE-2026-11519 A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /P… Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.0 CVE-2026-11500 A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authenticat… Patch available Fix from $1,6002026-06-08 MEDIUM 6.3 CVE-2026-11476 A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this iss… Mitigation only Fix from $1,6002026-06-08 HIGH 7.3 CVE-2026-11462 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/St… Patch available Fix from $1,9502026-06-07 MEDIUM 6.3 CVE-2026-11461 A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state… Mitigation only Fix from $1,6002026-06-07 MEDIUM 6.3 CVE-2026-11439 A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the compon… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.3 CVE-2026-11440 A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.3 CVE-2026-11441 A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the c… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.3 CVE-2026-11438 A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. Th… Mitigation only Fix from $1,6002026-06-06 CRITICAL 9.8 CVE-2026-10580 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all ve… Mitigation only Fix from $2,3002026-06-05 MEDIUM 6.3 CVE-2026-11336 A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8e… Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.3 CVE-2026-10876 A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This… No fix yet Fix from $1,6002026-06-05 HIGH 7.5 CVE-2026-48579 Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. Exchange Online Mitigation only Fix from $1,9502026-06-04 HIGH 7.1 CVE-2026-41522 Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2026-10693 A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functio… Mitigation only Fix from $1,6002026-06-03