Vulnerability index

Browse CVEs

5,746 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.3
CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

Patch available
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16324

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-62414

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 8.7
CVE-2026-60030

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.2
CVE-2026-46415

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to vers…

Patch available
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-12972

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-16201

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.5
CVE-2026-51083

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privilege…

No fix yet
Fix from $1,600 2026-07-17
Argo Workflows CRITICAL 9.9
CVE-2026-54526

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow…

Fix: 3.7.15 / 4.0.6+
Fix from $2,300 2026-07-16
Unclassified HIGH 8.1
CVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUr…

Patch available
Fix from $1,950 2026-07-16
Dfx Server MEDIUM 6.3
CVE-2026-35148

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form…

Fix: after 2.5
Fix from $1,600 2026-07-16
Build Of Keycloak HIGH 8.1
CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.8
CVE-2026-62314

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.…

Patch available
Fix from $1,600 2026-07-15
Unclassified HIGH 8.5
CVE-2026-55234

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-45313

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.2
CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…

Mitigation only
Fix from $2,300 2026-07-15
Roomos HIGH 8.8
CVE-2026-20150

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…

Fix: 11.32.6.0 / 11.39.1.1+
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-47164

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only…

Patch available
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.5
CVE-2026-36035

Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat…

Mitigation only
Fix from $1,600 2026-07-14
Configuration Manager 2503 HIGH 8.8
CVE-2026-47301

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.8
CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Fix: 2.111.4+
Fix from $2,300 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-58545

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-57088

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.20348.5386+
Fix from $1,950 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-50495

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14