Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-34171 | 1 Icewhale | 1 Casaos | 2026-02-26 | N/A | 5.3 MEDIUM |
|
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which reveals installed applications and configuration details. Additionally, /v1/sys/debug discloses host operating system, kernel, hardware, and storage information. The endpoints also retur ...
Show More |
|||||
| CVE-2026-25387 | 2026-02-26 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.
|
|||||
| CVE-2026-25363 | 2026-02-26 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11.
|
|||||
| CVE-2026-25329 | 2026-02-26 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.
|
|||||
| CVE-2026-23548 | 2026-02-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.25.
|
|||||
| CVE-2026-23545 | 2026-02-26 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through <= 3.0.4.
|
|||||
| CVE-2025-53217 | 2026-02-26 | N/A | 7.6 HIGH | ||
|
Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO WP Builder: from n/a through <= 2.0.2.
|
|||||
| CVE-2026-25370 | 2026-02-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.
|
|||||
| CVE-2026-23543 | 2026-02-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5.
|
|||||
| CVE-2024-43228 | 2026-02-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a through <= 2.2.5.3.
|
|||||
| CVE-2026-28193 | 1 Jetbrains | 1 Youtrack | 2026-02-26 | N/A | 8.8 HIGH |
|
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
|
|||||
| CVE-2026-27468 | 1 Joinmastodon | 1 Mastodon | 2026-02-26 | N/A | 8.2 HIGH |
|
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to backfill content did not check properly whether the FASP was actually approved. This only affects Mastodon servers that have opted in to testing the experimental FASP feature by setting the environment variable `EXPERIM ...
Show More |
|||||
| CVE-2025-15563 | 1 Nestersoft | 1 Worktime | 2026-02-26 | N/A | 5.3 MEDIUM |
|
Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.
|
|||||
| CVE-2025-67973 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.
|
|||||
| CVE-2025-67969 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1.
|
|||||
| CVE-2025-67547 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in uixthemes Konte konte allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Konte: from n/a through <= 2.4.6.
|
|||||
| CVE-2025-68025 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Addonify Addonify Floating Cart For WooCommerce addonify-floating-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify Floating Cart For WooCommerce: from n/a through <= 1.2.17.
|
|||||
| CVE-2025-68023 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Addonify Addonify – Compare Products For WooCommerce addonify-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – Compare Products For WooCommerce: from n/a through <= 1.1.17.
|
|||||
| CVE-2025-68021 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.5.
|
|||||
| CVE-2025-67994 | 2026-02-25 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.
|
|||||
| CVE-2025-67975 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in aDirectory aDirectory adirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects aDirectory: from n/a through <= 3.0.3.
|
|||||
| CVE-2025-68048 | 2026-02-25 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.
|
|||||
| CVE-2025-68042 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.1.
|
|||||
| CVE-2025-68032 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced WC Analytics: from n/a through <= 3.19.0.
|
|||||
| CVE-2025-68028 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.
|
|||||
| CVE-2023-6394 | 2 Quarkus, Redhat | 2 Quarkus, Build Of Quarkus | 2026-02-25 | N/A | 7.4 HIGH |
|
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
|
|||||
| CVE-2025-68837 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5.
|
|||||
| CVE-2025-68564 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in sendy Sendy sendy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendy: from n/a through <= 3.4.2.
|
|||||
| CVE-2021-0642 | 1 Google | 1 Android | 2026-02-25 | 4.3 MEDIUM | 5.5 MEDIUM |
|
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-185126149
|
|||||
| CVE-2021-0641 | 1 Google | 1 Android | 2026-02-25 | 2.1 LOW | 5.5 MEDIUM |
|
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185235454
|
|||||
| CVE-2026-27111 | 1 Akuity | 1 Kargo | 2026-02-25 | N/A | 5.0 MEDIUM |
|
Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-standard Kubernetes "dolphin verb" -- that gates the ability to advance Freight through a promotion pipeline. This verb exists to separate the ability to manage promotion-related resources from the ability to trigger promotions, enabling fine-grained access control over what is often a sensitive operation. The promote verb is correctly enforced in K ...
Show More |
|||||
| CVE-2025-69303 | 2026-02-25 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ModelTheme Framework: from n/a through <= 1.9.2.
|
|||||
| CVE-2025-69298 | 2026-02-25 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4.
|
|||||
| CVE-2024-54222 | 2026-02-25 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retrieve Embedded Sensitive Data.This issue affects Seraphinite Accelerator: from n/a through <= 2.22.15.
|
|||||
| CVE-2024-34438 | 2026-02-25 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19.
|
|||||
| CVE-2026-28195 | 1 Jetbrains | 1 Teamcity | 2026-02-25 | N/A | 4.3 MEDIUM |
|
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
|
|||||
| CVE-2026-25131 | 1 Open-emr | 1 Openemr | 2026-02-25 | N/A | 8.8 HIGH |
|
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add and modify procedure types without proper authorization. This vulnerability is present in the /openemr/interface/orders/types_edit.php endpoint. Version 8.0.0 contains a patch.
|
|||||
| CVE-2026-25609 | 1 Mongodb | 1 Mongodb | 2026-02-25 | N/A | 5.4 MEDIUM |
|
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.
|
|||||
| CVE-2026-25124 | 1 Open-emr | 1 Openemr | 2026-02-25 | N/A | 6.5 MEDIUM |
|
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR application is vulnerable to an access control flaw that allows low-privileged users, such as receptionists, to export the entire message list containing sensitive patient and user data. The vulnerability lies in the message_list.php report export functionality, where there is no permission check before executing sensitive database queries. The only control ...
Show More |
|||||
| CVE-2025-69381 | 2026-02-25 | N/A | 7.1 HIGH | ||
|
Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0.
|
|||||