Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Mastodon MEDIUM 5.4
CVE-2026-23964

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object re…

Fix: 4.3.18 / 4.4.12+
Fix from $1,600 2026-01-22
Mastodon MEDIUM 5.3
CVE-2026-23961

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent …

Fix: 4.3.18 / 4.4.12+
Fix from $1,600 2026-01-22
External Secrets Operator HIGH 8.8
CVE-2026-22822

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in versi…

Fix: 1.2.0+
Fix from $1,950 2026-01-21
Mytube CRITICAL 9.8
CVE-2026-23837

MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions …

Fix: 1.7.66+
Fix from $2,300 2026-01-19
Devolutions Server HIGH 7.6
CVE-2026-1007

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects …

Fix: 2025.3.14.0+
Fix from $1,950 2026-01-19
Power Apps HIGH 8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Fix: 3.25121+
Fix from $1,950 2026-01-16
Web2print Tools MEDIUM 5.4
CVE-2026-23496

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se…

Fix: 5.2.2 / 6.1.1+
Fix from $1,600 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22909

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential…

Mitigation only
Fix from $2,300 2026-01-15
Unclassified HIGH 8.5
CVE-2025-66005

Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information le…

Mitigation only
Fix from $1,950 2026-01-14
Unclassified MEDIUM 5.3
CVE-2025-15513

The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatRe…

Mitigation only
Fix from $1,600 2026-01-14
Dreamweaver HIGH 7.8
CVE-2026-21274

Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution …

Fix: 21.7+
Fix from $1,950 2026-01-13
TYPO3 MEDIUM 6.5
CVE-2025-59020

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the…

Fix: 10.4.55 / 11.5.49+
Fix from $1,600 2026-01-13
Documents HIGH 8.1
CVE-2025-41078

Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other use…

Fix: 1.9.2 / 3.7.139+
Fix from $1,950 2026-01-12
Unclassified MEDIUM 5.3
CVE-2026-0831

The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate inpu…

Mitigation only
Fix from $1,600 2026-01-10
Ghost HIGH 8.1
CVE-2026-22595

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of St…

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Mf258k Pro Firmware HIGH 8.8
CVE-2025-66315

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att…

Mitigation only
Fix from $1,950 2026-01-09
Soft Serve MEDIUM 5.4
CVE-2026-22253

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint all…

Fix: 0.11.2+
Fix from $1,600 2026-01-08
Kirby MEDIUM 5.7
CVE-2026-21896

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This …

Fix: 5.2.2+
Fix from $1,600 2026-01-08
Ecase Audit HIGH 7.6
CVE-2026-22230

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have …

Fix: 11.14.1.0+
Fix from $1,950 2026-01-08
Rustfs HIGH 8.8
CVE-2026-22042

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `E…

No fix yet
Fix from $1,950 2026-01-08
Unclassified MEDIUM 5.3
CVE-2025-14352

The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.p…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 8.8
CVE-2020-36920

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges throug…

No fix yet
Fix from $1,950 2026-01-06
Coolify HIGH 8.0
CVE-2025-64421

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Opencti CRITICAL 9.1
CVE-2025-61781

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…

Fix: 6.8.1+
Fix from $2,300 2026-01-05
Media Server HIGH 7.1
CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

Fix: after 1.42.2.10156
Fix from $1,950 2026-01-02
Online Course Registration HIGH 8.8
CVE-2025-15406

A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authoriz…

Fix: after 3.1
Fix from $1,950 2026-01-01
Small Crm HIGH 8.8
CVE-2025-15390

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation …

Fix: after 4.0
Fix from $1,950 2025-12-31
Unclassified MEDIUM 5.3
CVE-2025-14987

When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkf…

Mitigation only
Fix from $1,600 2025-12-30
Jeecg Boot HIGH 7.5
CVE-2025-15126

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position…

Fix: after 3.9.0
Fix from $1,950 2025-12-28
Gitea MEDIUM 5.3
CVE-2025-68940

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Fix: 1.22.5+
Fix from $1,600 2025-12-26