Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2026-5574 A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr… Hi Led Wr120 G2 Firmware No fix yet Fix from $2,3002026-04-05 HIGH 7.1 CVE-2026-3445 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul… Mitigation only Fix from $1,9502026-04-04 MEDIUM 6.5 CVE-2026-3571 The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a… Mitigation only Fix from $1,6002026-04-04 MEDIUM 5.4 CVE-2026-34766 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and… Electron 38.8.6 / 39.8.0+ Fix from $1,6002026-04-04 HIGH 7.5 CVE-2026-27833 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered wi… Piwigo 16.3.0+ Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-35561 Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow … Athena Odbc 2.1.0.0+ Fix from $2,3002026-04-03 MEDIUM 5.3 CVE-2026-25742 Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before… Zulip 11.6+ Fix from $1,6002026-04-03 HIGH 7.5 CVE-2026-22663 prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and … Prompts.chat 2026-03-25+ Fix from $1,9502026-04-03 HIGH 8.1 CVE-2026-34759 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered witho… Oneuptime 10.0.42+ Fix from $1,9502026-04-02 CRITICAL 9.4 CVE-2026-33950 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera… Signal K Server 2.24.0+ Fix from $2,3002026-04-02 HIGH 8.0 CVE-2026-20155 A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attac… Evolved Programmable Network Manager 8.1.2+ Fix from $1,9502026-04-01 MEDIUM 5.0 CVE-2026-5175 Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete thei… Devolutions Server 2026.1.12.0+ Fix from $1,6002026-04-01 MEDIUM 5.0 CVE-2026-4925 Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and… Devolutions Server 2026.1.12.0+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-34737 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible … Avideo after 26.0 Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-34395 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform user… Avideo after 26.0 Fix from $1,6002026-03-31 HIGH 8.1 CVE-2026-4818 In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage… Flx 4.1.0+ Fix from $1,9502026-03-31 MEDIUM 5.3 CVE-2026-1797 The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… Mitigation only Fix from $1,6002026-03-31 HIGH 8.2 CVE-2026-34042 act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connection… Patch available Fix from $1,9502026-03-31 MEDIUM 5.4 CVE-2025-15445 The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in… Mitigation only Fix from $1,6002026-03-28 HIGH 8.8 CVE-2026-34046 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l… Langflow Base 0.5.1 / 1.5.0+ Fix from $1,9502026-03-27 MEDIUM 5.4 CVE-2026-33887 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could v… Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-29180 Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team ma… Fleet 4.81.1+ Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-34369 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVi… Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 6.3 CVE-2026-34245 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endp… Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-34247 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authentica… Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 5.3 CVE-2026-5022 The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated u… Langflow Mitigation only Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-5025 The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only… Langflow Mitigation only Fix from $1,6002026-03-27 MEDIUM 5.3 CVE-2026-33759 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full … Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 5.3 CVE-2026-33761 WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any … Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-4309 Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the setting… Aterm Wg2600hs Firmware 1.3.2 / 1.4.2+ Fix from $1,6002026-03-27