Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2026-45345 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's m… Open Webui 0.5.7+ Fix from $1,6002026-05-15 HIGH 7.2 CVE-2026-45371 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated… Mitigation only Fix from $1,9502026-05-14 HIGH 8.6 CVE-2026-44504 Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a … Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.1 CVE-2026-43515 Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 HIGH 8.1 CVE-2026-43983 Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken… Pocket Id 2.6.0+ Fix from $1,9502026-05-12 HIGH 8.7 CVE-2026-43912 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_u… Vaultwarden 1.35.5+ Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-42875 External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Na… Mitigation only Fix from $1,6002026-05-11 HIGH 8.1 CVE-2026-42609 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o… Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-8241 A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of … Mitigation only Fix from $1,6002026-05-10 MEDIUM 6.5 CVE-2026-42202 nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{res… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2026-33823 Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Teams No fix yet Fix from $1,6002026-05-07 CRITICAL 9.8 CVE-2026-30496 The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated … Mitigation only Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-30495 The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network w… Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.3 CVE-2026-7782 A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Cli… Mitigation only Fix from $1,6002026-05-04 MEDIUM 5.3 CVE-2026-41572 Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploa… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7713 A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token … Patch available Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7709 A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_au… Mitigation only Fix from $1,6002026-05-03 MEDIUM 5.3 CVE-2026-7702 A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId… No fix yet Fix from $1,6002026-05-03 MEDIUM 6.5 CVE-2026-7681 A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the … Mitigation only Fix from $1,6002026-05-03 HIGH 7.3 CVE-2026-7644 A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The man… Mitigation only Fix from $1,9502026-05-02 MEDIUM 5.4 CVE-2026-7631 A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Regist… Mitigation only Fix from $1,6002026-05-02 MEDIUM 5.3 CVE-2026-6449 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and inc… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7602 A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the … Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7510 A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark… Patch available Fix from $1,6002026-04-30 HIGH 7.3 CVE-2026-7505 A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This man… Patch available Fix from $1,9502026-04-30 MEDIUM 5.4 CVE-2026-7502 A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/… Patch available Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-2892 The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the '… Mitigation only Fix from $1,9502026-04-30 MEDIUM 5.6 CVE-2026-7292 A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAge… Mitigation only Fix from $1,6002026-04-28 HIGH 8.8 CVE-2026-5781 An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user wi… Minerva Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.4 CVE-2026-7145 A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/Workspa… Mitigation only Fix from $1,6002026-04-27