Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2026-23964 Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object re… Mastodon 4.3.18 / 4.4.12+ Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2026-23961 Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent … Mastodon 4.3.18 / 4.4.12+ Fix from $1,6002026-01-22 HIGH 8.8 CVE-2026-22822 External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in versi… External Secrets Operator 1.2.0+ Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2026-23837 MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions … Mytube 1.7.66+ Fix from $2,3002026-01-19 HIGH 7.6 CVE-2026-1007 Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects … Devolutions Server 2025.3.14.0+ Fix from $1,9502026-01-19 HIGH 8.0 CVE-2026-20960 Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. Power Apps 3.25121+ Fix from $1,9502026-01-16 MEDIUM 5.4 CVE-2026-23496 Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se… Web2print Tools 5.2.2 / 6.1.1+ Fix from $1,6002026-01-15 CRITICAL 9.1 CVE-2026-22909 Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential… Tdc X401gl Firmware Mitigation only Fix from $2,3002026-01-15 HIGH 8.5 CVE-2025-66005 Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information le… Mitigation only Fix from $1,9502026-01-14 MEDIUM 5.3 CVE-2025-15513 The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatRe… Mitigation only Fix from $1,6002026-01-14 HIGH 7.8 CVE-2026-21274 Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution … Dreamweaver 21.7+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2025-59020 By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the… TYPO3 10.4.55 / 11.5.49+ Fix from $1,6002026-01-13 HIGH 8.1 CVE-2025-41078 Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other use… Documents 1.9.2 / 3.7.139+ Fix from $1,9502026-01-12 MEDIUM 5.3 CVE-2026-0831 The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate inpu… Mitigation only Fix from $1,6002026-01-10 HIGH 8.1 CVE-2026-22595 Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of St… Ghost 5.130.6 / 6.11.0+ Fix from $1,9502026-01-10 HIGH 8.8 CVE-2025-66315 There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att… Mf258k Pro Firmware Mitigation only Fix from $1,9502026-01-09 MEDIUM 5.4 CVE-2026-22253 Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint all… Soft Serve 0.11.2+ Fix from $1,6002026-01-08 MEDIUM 5.7 CVE-2026-21896 Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This … Kirby 5.2.2+ Fix from $1,6002026-01-08 HIGH 7.6 CVE-2026-22230 OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have … Ecase Audit 11.14.1.0+ Fix from $1,9502026-01-08 HIGH 8.8 CVE-2026-22042 RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `E… Rustfs No fix yet Fix from $1,9502026-01-08 MEDIUM 5.3 CVE-2025-14352 The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.p… Mitigation only Fix from $1,6002026-01-07 HIGH 8.8 CVE-2020-36920 iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges throug… No fix yet Fix from $1,9502026-01-06 HIGH 8.0 CVE-2025-64421 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be… Coolify 4.0.0+ Fix from $1,9502026-01-05 CRITICAL 9.1 CVE-2025-61781 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo… Opencti 6.8.1+ Fix from $2,3002026-01-05 HIGH 7.1 CVE-2025-69414 Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token. Media Server after 1.42.2.10156 Fix from $1,9502026-01-02 HIGH 8.8 CVE-2025-15406 A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authoriz… Online Course Registration after 3.1 Fix from $1,9502026-01-01 HIGH 8.8 CVE-2025-15390 A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation … Small Crm after 4.0 Fix from $1,9502025-12-31 MEDIUM 5.3 CVE-2025-14987 When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkf… Mitigation only Fix from $1,6002025-12-30 HIGH 7.5 CVE-2025-15126 A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-28 MEDIUM 5.3 CVE-2025-68940 In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. Gitea 1.22.5+ Fix from $1,6002025-12-26