Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Vantara Pentaho Data Integration And Analytics CRITICAL 9.1
CVE-2025-11158

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT …

Fix: 10.2.0.6+
Fix from $2,300 2026-03-10
Siyuan HIGH 7.1
CVE-2026-30926

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note …

Fix: 3.5.10+
Fix from $1,950 2026-03-10
Budibase HIGH 8.8
CVE-2026-25045

Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalatio…

Fix: after 3.32.3
Fix from $1,950 2026-03-09
Devolutions Server MEDIUM 5.9
CVE-2026-3638

Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated us…

Fix: 2025.3.12.0+
Fix from $1,600 2026-03-09
Universal Bacnet Router Firmware CRITICAL 9.1
CVE-2025-41764

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u…

Fix: 6.0.1.0+
Fix from $2,300 2026-03-09
Universal Bacnet Router Firmware CRITICAL 9.1
CVE-2025-41765

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d…

Fix: 6.0.1.0+
Fix from $2,300 2026-03-09
Computer Laboratory Management System HIGH 8.8
CVE-2026-3770

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site …

No fix yet
Fix from $1,950 2026-03-08
Parse Server MEDIUM 5.9
CVE-2026-30850

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, th…

Fix: 8.6.9 / 9.5.0+
Fix from $1,600 2026-03-07
Flowise HIGH 8.8
CVE-2026-30823

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, lea…

Fix: 3.0.13+
Fix from $1,950 2026-03-07
Homarr HIGH 7.5
CVE-2026-27796

Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing un…

Fix: 1.54.0+
Fix from $1,950 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-1650

The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_field…

Mitigation only
Fix from $1,600 2026-03-07
Unclassified MEDIUM 5.3
CVE-2026-2371

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Mitigation only
Fix from $1,600 2026-03-07
Vito HIGH 8.8
CVE-2026-29789

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missi…

Fix: 3.20.3+
Fix from $1,950 2026-03-06
Wekan HIGH 8.2
CVE-2026-30845

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr…

Fix: 8.33+
Fix from $1,950 2026-03-06
Siyuan HIGH 8.8
CVE-2026-29073

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a…

Fix: after 3.5.9
Fix from $1,950 2026-03-06
Unclassified CRITICAL 9.8
CVE-2026-2446

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated use…

Mitigation only
Fix from $2,300 2026-03-06
Agent HIGH 7.1
CVE-2025-11791

Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protec…

Fix: 17.0.41186+
Fix from $1,950 2026-03-06
Olivetin HIGH 7.5
CVE-2026-28790

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…

Fix: 3000.11.0+
Fix from $1,950 2026-03-05
Rustdesk HIGH 8.1
CVE-2026-30797

Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme han…

Fix: after 1.4.5
Fix from $1,950 2026-03-05
Unclassified HIGH 8.8
CVE-2026-1720

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitra…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 8.1
CVE-2026-1321

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. Thi…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-28104

Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by A…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified MEDIUM 6.3
CVE-2026-28071

Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This…

No fix yet
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2026-28076

Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-28038

Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2026-27386

Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configure…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 7.5
CVE-2026-27388

Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configure…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 7.3
CVE-2026-27396

Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-27362

Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2026-27374

Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access C…

Mitigation only
Fix from $1,950 2026-03-05