Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Hi Led Wr120 G2 Firmware CRITICAL 9.1
CVE-2026-5574

A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr…

No fix yet
Fix from $2,300 2026-04-05
Unclassified HIGH 7.1
CVE-2026-3445

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

Mitigation only
Fix from $1,950 2026-04-04
Unclassified MEDIUM 6.5
CVE-2026-3571

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Mitigation only
Fix from $1,600 2026-04-04
Electron MEDIUM 5.4
CVE-2026-34766

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…

Fix: 38.8.6 / 39.8.0+
Fix from $1,600 2026-04-04
Piwigo HIGH 7.5
CVE-2026-27833

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered wi…

Fix: 16.3.0+
Fix from $1,950 2026-04-03
Athena Odbc CRITICAL 9.8
CVE-2026-35561

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow …

Fix: 2.1.0.0+
Fix from $2,300 2026-04-03
Zulip MEDIUM 5.3
CVE-2026-25742

Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before…

Fix: 11.6+
Fix from $1,600 2026-04-03
Prompts.chat HIGH 7.5
CVE-2026-22663

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and …

Fix: 2026-03-25+
Fix from $1,950 2026-04-03
Oneuptime HIGH 8.1
CVE-2026-34759

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered witho…

Fix: 10.0.42+
Fix from $1,950 2026-04-02
Signal K Server CRITICAL 9.4
CVE-2026-33950

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…

Fix: 2.24.0+
Fix from $2,300 2026-04-02
Evolved Programmable Network Manager HIGH 8.0
CVE-2026-20155

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attac…

Fix: 8.1.2+
Fix from $1,950 2026-04-01
Devolutions Server MEDIUM 5.0
CVE-2026-5175

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete thei…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01
Devolutions Server MEDIUM 5.0
CVE-2026-4925

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01
Avideo MEDIUM 6.5
CVE-2026-34737

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible …

Fix: after 26.0
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.5
CVE-2026-34395

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform user…

Fix: after 26.0
Fix from $1,600 2026-03-31
Flx HIGH 8.1
CVE-2026-4818

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage…

Fix: 4.1.0+
Fix from $1,950 2026-03-31
Unclassified MEDIUM 5.3
CVE-2026-1797

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified HIGH 8.2
CVE-2026-34042

act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connection…

Patch available
Fix from $1,950 2026-03-31
Unclassified MEDIUM 5.4
CVE-2025-15445

The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in…

Mitigation only
Fix from $1,600 2026-03-28
Langflow Base HIGH 8.8
CVE-2026-34046

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l…

Fix: 0.5.1 / 1.5.0+
Fix from $1,950 2026-03-27
Statamic MEDIUM 5.4
CVE-2026-33887

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could v…

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Fleet HIGH 8.8
CVE-2026-29180

Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team ma…

Fix: 4.81.1+
Fix from $1,950 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-34369

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVi…

Fix: after 26.0
Fix from $1,600 2026-03-27
Avideo MEDIUM 6.3
CVE-2026-34245

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endp…

Fix: after 26.0
Fix from $1,600 2026-03-27
Avideo MEDIUM 5.4
CVE-2026-34247

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authentica…

Fix: after 26.0
Fix from $1,600 2026-03-27
Langflow MEDIUM 5.3
CVE-2026-5022

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated u…

Mitigation only
Fix from $1,600 2026-03-27
Langflow MEDIUM 6.5
CVE-2026-5025

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only…

Mitigation only
Fix from $1,600 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-33759

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full …

Fix: after 26.0
Fix from $1,600 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-33761

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any …

Fix: after 26.0
Fix from $1,600 2026-03-27
Aterm Wg2600hs Firmware MEDIUM 6.5
CVE-2026-4309

Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the setting…

Fix: 1.3.2 / 1.4.2+
Fix from $1,600 2026-03-27