Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2026-24851 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1… Helm Charts 0.2.51 / 1.11.3+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-23632 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write… Gogs 0.13.4+ Fix from $1,6002026-02-06 HIGH 7.2 CVE-2026-23572 Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass … Mitigation only Fix from $1,9502026-02-05 MEDIUM 6.5 CVE-2025-70997 A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permiss… Eladmin after 2.7 Fix from $1,6002026-02-04 CRITICAL 9.8 CVE-2025-67856 A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges… Moodle 4.1.22 / 4.4.12+ Fix from $2,3002026-02-03 MEDIUM 5.4 CVE-2025-15395 IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to v… Jazz Foundation Mitigation only Fix from $1,6002026-02-02 MEDIUM 5.3 CVE-2026-1734 A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/… Crmeb after 5.6.3 Fix from $1,6002026-02-02 MEDIUM 5.3 CVE-2025-15525 The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect autho… Mitigation only Fix from $1,6002026-01-31 HIGH 8.8 CVE-2026-25040 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level use… Budibase after 3.26.3 Fix from $1,9502026-01-29 CRITICAL 9.1 CVE-2026-22806 vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4… Mitigation only Fix from $2,3002026-01-29 HIGH 8.8 CVE-2026-24780 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.44+ Fix from $1,9502026-01-29 MEDIUM 6.5 CVE-2026-24742 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensit… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-69218 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploa… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-69289 Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 … Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-68666 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-68933 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moder… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-13985 Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0. Entity Share 3.13.0+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-68660 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated u… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 HIGH 8.8 CVE-2020-36969 M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin para… M\/monit No fix yet Fix from $1,9502026-01-28 MEDIUM 6.5 CVE-2026-1514 Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing authenticated remote attackers… Mitigation only Fix from $1,6002026-01-28 HIGH 7.2 CVE-2026-24748 Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was found with authentication check… Kargo 1.6.3 / 1.7.7+ Fix from $1,9502026-01-27 CRITICAL 9.9 CVE-2026-24740 Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict… Dozzle 9.0.3+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2020-36948 VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attac… Mitigation only Fix from $2,3002026-01-27 HIGH 8.1 CVE-2026-21721 The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who… Grafana 11.6.9 / 12.0.8+ Fix from $1,9502026-01-27 HIGH 8.7 CVE-2026-24480 QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commi… Patch available Fix from $1,9502026-01-27 MEDIUM 5.3 CVE-2026-24003 EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification includi… Everest after 2025.12.1 Fix from $1,6002026-01-26 HIGH 8.8 CVE-2026-24428 Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a… W30e Firmware after 16.01.0.19 Fix from $1,9502026-01-26 CRITICAL 9.1 CVE-2025-66719 An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/… Nrf Patch available Fix from $2,3002026-01-23 HIGH 8.8 CVE-2025-14866 The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a mi… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2025-13928 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could … GitLab 18.6.4 / 18.7.2+ Fix from $1,9502026-01-22