Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2025-11158 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT … Vantara Pentaho Data Integration And Analytics 10.2.0.6+ Fix from $2,3002026-03-10 HIGH 7.1 CVE-2026-30926 SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note … Siyuan 3.5.10+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-25045 Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalatio… Budibase after 3.32.3 Fix from $1,9502026-03-09 MEDIUM 5.9 CVE-2026-3638 Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated us… Devolutions Server 2025.3.12.0+ Fix from $1,6002026-03-09 CRITICAL 9.1 CVE-2025-41764 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 CRITICAL 9.1 CVE-2025-41765 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 HIGH 8.8 CVE-2026-3770 A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site … Computer Laboratory Management System No fix yet Fix from $1,9502026-03-08 MEDIUM 5.9 CVE-2026-30850 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, th… Parse Server 8.6.9 / 9.5.0+ Fix from $1,6002026-03-07 HIGH 8.8 CVE-2026-30823 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, lea… Flowise 3.0.13+ Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-27796 Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing un… Homarr 1.54.0+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-1650 The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_field… Mitigation only Fix from $1,6002026-03-07 MEDIUM 5.3 CVE-2026-2371 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … Mitigation only Fix from $1,6002026-03-07 HIGH 8.8 CVE-2026-29789 Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missi… Vito 3.20.3+ Fix from $1,9502026-03-06 HIGH 8.2 CVE-2026-30845 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr… Wekan 8.33+ Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-29073 SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a… Siyuan after 3.5.9 Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-2446 The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated use… Mitigation only Fix from $2,3002026-03-06 HIGH 7.1 CVE-2025-11791 Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protec… Agent 17.0.41186+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-28790 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term… Olivetin 3000.11.0+ Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-30797 Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme han… Rustdesk after 1.4.5 Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-1720 The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitra… Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-1321 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. Thi… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-28104 Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by A… Mitigation only Fix from $1,6002026-03-05 MEDIUM 6.3 CVE-2026-28071 Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This… No fix yet Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-28076 Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-28038 Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Co… Mitigation only Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-27386 Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configure… Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-27388 Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configure… Mitigation only Fix from $1,9502026-03-05 HIGH 7.3 CVE-2026-27396 Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-27362 Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-27374 Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access C… Mitigation only Fix from $1,9502026-03-05