Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 8.2
CVE-2026-59501

CWE-284: Improper Access Control

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.6
CVE-2026-59505

CWE-284: Improper Access Control

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-13328

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is als…

No fix yet
Fix from $4,000 2026-08-13
Informix Dynamic Server HIGH 7.8
CVE-2026-13367

IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.

No fix yet
Fix from $4,900 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-59914

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low pri…

No fix yet
Fix from $4,900 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-59917

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attac…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-67287

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on …

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-67284

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.9
CVE-2026-67283

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-16538

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wall…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.2
CVE-2026-13171

The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticate…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-73212

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…

No fix yet
Fix from $4,000 2026-08-11
Windows 10 22h2 HIGH 7.8
CVE-2026-66804

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19045.7663 / 10.0.26100.9106+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-65773

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Github Copilot Chat MEDIUM 6.5
CVE-2026-65675

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.5
CVE-2026-20898

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of pri…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.4
CVE-2026-20789

Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.3
CVE-2026-20741

Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unprivileged sof…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.2
CVE-2026-20716

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72600

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72601

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally iden…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72561

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-72563

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to oth…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-72595

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to othe…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-72596

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72554

A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.1
CVE-2026-72555

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to fal…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-72693

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72909

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions pa…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18951

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme…

No fix yet
Fix from $4,900 2026-08-10