Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified CRITICAL 9.9
CVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-73372

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access che…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-72531

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.6
CVE-2026-54730

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow with…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-73371

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.5
CVE-2026-71574

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-72532

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2026-50138

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird …

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2024-14046

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-68004

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-73061

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-19711

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allow…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19918

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-14229

The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of…

Fix unknown
Fix from $4,000 2026-08-15
Unclassified MEDIUM 5.1
CVE-2026-71570

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_ic…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72837

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers wi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.6
CVE-2026-73664

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-58440

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-58507

Private Repository Existence Disclosure via go-get Meta Endpoint

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.1
CVE-2026-58437

Repository Visibility Manipulation via Git Push Options

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-58439

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58417

REST API exposes organization membership of private organizations to public

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-56654

Privilege Escalation via Access Token Scope Escalation in API

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.2
CVE-2026-56657

Gitea SSH Key Parser Denial of Service

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.2
CVE-2026-56755

Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-55986

Email Management API Bypasses ManageCredentials Feature Restrictions

No fix yet
Fix from $4,000 2026-08-13