Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified CRITICAL 9.1
CVE-2025-15484

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthent…

Mitigation only
Fix from $2,300 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71279

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the se…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Minio HIGH 7.1
CVE-2026-34204

MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any auth…

Fix: 2026-03-26t21-24-40z+
Fix from $1,950 2026-03-31
Openolat CRITICAL 9.8
CVE-2026-31946

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version …

Fix: 20.2.5+
Fix from $2,300 2026-03-30
Lollms CRITICAL 9.8
CVE-2026-0558

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/fil…

Fix: after 2.1.0
Fix from $2,300 2026-03-29
Unclassified HIGH 7.3
CVE-2026-5000

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of th…

Mitigation only
Fix from $1,950 2026-03-28
Fleet MEDIUM 6.5
CVE-2026-34389

Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provid…

Fix: 4.81.1+
Fix from $1,600 2026-03-27
Xagent HIGH 7.5
CVE-2026-4959

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of t…

No fix yet
Fix from $1,950 2026-03-27
Dovecot MEDIUM 5.9
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the conf…

Fix: 2.3.22.1 / 2.4.3+
Fix from $1,600 2026-03-27
Incus HIGH 8.8
CVE-2026-33898

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the a…

Fix: 6.23.0+
Fix from $1,950 2026-03-27
Nats Server MEDIUM 5.4
CVE-2026-33246

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
N8n HIGH 7.5
CVE-2026-33665

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linke…

Fix: 1.121.0 / 2.4.0+
Fix from $1,950 2026-03-25
Nats Server MEDIUM 6.5
CVE-2026-33215

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Pr…

Fix: 2.11.15 / 2.12.5+
Fix from $1,600 2026-03-24
Pyload Ng MEDIUM 6.5
CVE-2026-33314

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @loc…

Fix: 0.5.0b3.dev97+
Fix from $1,600 2026-03-24
Minio CRITICAL 9.8
CVE-2026-33322

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusio…

Fix: 2026-03-17t21-25-16z+
Fix from $2,300 2026-03-24
Parse Server CRITICAL 9.1
CVE-2026-33409

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, …

Fix: 8.6.52 / 9.6.0+
Fix from $2,300 2026-03-24
Vikunja MEDIUM 5.7
CVE-2026-33473

Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA ca…

Fix: 2.2.1+
Fix from $1,600 2026-03-24
Unclassified HIGH 8.1
CVE-2026-4021

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2026-03-24
Avideo CRITICAL 9.4
CVE-2026-33716

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/stand…

Fix: after 26.0
Fix from $2,300 2026-03-23
Avideo HIGH 7.5
CVE-2026-33512

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authe…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified MEDIUM 5.6
CVE-2026-4592

A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-cod…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.0
CVE-2026-4583

A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component B…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.0
CVE-2026-4582

A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionalit…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4562

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the …

Mitigation only
Fix from $1,950 2026-03-23
Unclassified MEDIUM 5.0
CVE-2026-2756

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Suc…

Mitigation only
Fix from $1,600 2026-03-21
Traefik MEDIUM 5.3
CVE-2026-32305

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS byp…

Fix: 2.11.41+
Fix from $1,600 2026-03-20
Frigate HIGH 8.8
CVE-2026-33124

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated…

Fix: 0.17.0+
Fix from $1,950 2026-03-20
Unclassified MEDIUM 6.3
CVE-2026-4476

A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown function of the file home/web/ip…

Mitigation only
Fix from $1,600 2026-03-20
Siyuan HIGH 7.5
CVE-2026-32815

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unauthenticated connections when s…

Fix: 3.6.1+
Fix from $1,950 2026-03-19
Step Ca CRITICAL 10.0
CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag…

Fix: 0.30.0+
Fix from $2,300 2026-03-19