Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.1 CVE-2026-33398 NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is … Mitigation only Fix from $1,9502026-06-02 MEDIUM 5.4 CVE-2026-10284 A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-10285 A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordU… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-45275 Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app t… Approval 2.7.2+ Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0072 In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local … Android Xr Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10269 A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardG… Patch available Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-10272 A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown f… Mitigation only Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-10236 A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes… Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.4 CVE-2026-10218 A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.g… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10212 A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. … Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10211 A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tool… Mitigation only Fix from $1,6002026-06-01 CRITICAL 9.9 CVE-2026-47744 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel… Mitigation only Fix from $2,3002026-05-29 HIGH 8.1 CVE-2026-47740 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were call… Patch available Fix from $1,9502026-05-29 MEDIUM 5.3 CVE-2026-45620 WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an e… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-45297 OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-47673 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify tha… Hono 4.12.21+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2025-68712 SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. A… Mitigation only Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-6938 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. Db2 after 12.1.4 Fix from $1,9502026-05-27 MEDIUM 5.5 CVE-2025-43289 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app m… macOS 14.8 / 15.7+ Fix from $1,6002026-05-26 MEDIUM 6.5 CVE-2026-46620 e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. Th… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-9484 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStu… Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9483 A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing … Mitigation only Fix from $1,6002026-05-25 HIGH 8.1 CVE-2026-9397 A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the componen… Mitigation only Fix from $1,9502026-05-24 MEDIUM 6.3 CVE-2026-9376 A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the com… Mitigation only Fix from $1,6002026-05-24 HIGH 7.5 CVE-2022-34363 Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application run… Unisphere For Powermax Virtual Appliance 10.0.0.2+ Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-45187 Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade t… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.3 CVE-2026-8786 A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i… Weknora after 0.3.6 Fix from $1,6002026-05-18 MEDIUM 6.3 CVE-2026-8747 A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of t… Mitigation only Fix from $1,6002026-05-17 MEDIUM 6.3 CVE-2026-8743 A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the compon… Open5gs after 2.7.6 Fix from $1,6002026-05-17 MEDIUM 5.4 CVE-2026-45365 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter pa… Open Webui 0.8.11+ Fix from $1,6002026-05-15