Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Helm Charts HIGH 8.8
CVE-2026-24851

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1…

Fix: 0.2.51 / 1.11.3+
Fix from $1,950 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-23632

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
Unclassified HIGH 7.2
CVE-2026-23572

Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass …

Mitigation only
Fix from $1,950 2026-02-05
Eladmin MEDIUM 6.5
CVE-2025-70997

A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permiss…

Fix: after 2.7
Fix from $1,600 2026-02-04
Moodle CRITICAL 9.8
CVE-2025-67856

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges…

Fix: 4.1.22 / 4.4.12+
Fix from $2,300 2026-02-03
Jazz Foundation MEDIUM 5.4
CVE-2025-15395

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to v…

Mitigation only
Fix from $1,600 2026-02-02
Crmeb MEDIUM 5.3
CVE-2026-1734

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/…

Fix: after 5.6.3
Fix from $1,600 2026-02-02
Unclassified MEDIUM 5.3
CVE-2025-15525

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect autho…

Mitigation only
Fix from $1,600 2026-01-31
Budibase HIGH 8.8
CVE-2026-25040

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level use…

Fix: after 3.26.3
Fix from $1,950 2026-01-29
Unclassified CRITICAL 9.1
CVE-2026-22806

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4…

Mitigation only
Fix from $2,300 2026-01-29
Autogpt Platform HIGH 8.8
CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.44+
Fix from $1,950 2026-01-29
Discourse MEDIUM 6.5
CVE-2026-24742

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensit…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Discourse MEDIUM 6.5
CVE-2025-69218

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploa…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Discourse MEDIUM 5.4
CVE-2025-69289

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 …

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Discourse MEDIUM 6.5
CVE-2025-68666

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Discourse MEDIUM 5.4
CVE-2025-68933

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moder…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Entity Share MEDIUM 5.3
CVE-2025-13985

Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.

Fix: 3.13.0+
Fix from $1,600 2026-01-28
Discourse MEDIUM 5.4
CVE-2025-68660

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated u…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
M\/monit HIGH 8.8
CVE-2020-36969

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin para…

No fix yet
Fix from $1,950 2026-01-28
Unclassified MEDIUM 6.5
CVE-2026-1514

Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing authenticated remote attackers…

Mitigation only
Fix from $1,600 2026-01-28
Kargo HIGH 7.2
CVE-2026-24748

Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was found with authentication check…

Fix: 1.6.3 / 1.7.7+
Fix from $1,950 2026-01-27
Dozzle CRITICAL 9.9
CVE-2026-24740

Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict…

Fix: 9.0.3+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2020-36948

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attac…

Mitigation only
Fix from $2,300 2026-01-27
Grafana HIGH 8.1
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who…

Fix: 11.6.9 / 12.0.8+
Fix from $1,950 2026-01-27
Unclassified HIGH 8.7
CVE-2026-24480

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commi…

Patch available
Fix from $1,950 2026-01-27
Everest MEDIUM 5.3
CVE-2026-24003

EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification includi…

Fix: after 2025.12.1
Fix from $1,600 2026-01-26
W30e Firmware HIGH 8.8
CVE-2026-24428

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a…

Fix: after 16.01.0.19
Fix from $1,950 2026-01-26
Nrf CRITICAL 9.1
CVE-2025-66719

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/…

Patch available
Fix from $2,300 2026-01-23
Unclassified HIGH 8.8
CVE-2025-14866

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a mi…

Mitigation only
Fix from $1,950 2026-01-23
GitLab HIGH 7.5
CVE-2025-13928

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could …

Fix: 18.6.4 / 18.7.2+
Fix from $1,950 2026-01-22