Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.3
CVE-2026-18969

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters t…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70612

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Langflow HIGH 8.1
CVE-2026-10547

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20304

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Ios Xe CRITICAL 9.0
CVE-2026-20267

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 6.3
CVE-2026-18927

A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.6
CVE-2026-70602

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Build Of Keycloak HIGH 8.1
CVE-2026-16102

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f…

Fix: 26.4.14 / 26.6.5+
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2025-70962

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication me…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.2
CVE-2026-71204

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application setti…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-16736

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrat…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-15230

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, a…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-67979

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary …

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-70481

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.3
CVE-2026-70476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18788

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-16547

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14816

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14848

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67970

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67975

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add…

No fix yet
Fix from $1,950 2026-08-03
Display And Peripheral Manager HIGH 7.8
CVE-2026-59912

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged atta…

Fix: 2.3.0.1005+
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.2
CVE-2026-15430

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …

No fix yet
Fix from $1,600 2026-08-03
Icontrol MEDIUM 5.3
CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-16563

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through i…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-15241

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15151

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users …

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-14315

The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing una…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-14822

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endp…

No fix yet
Fix from $1,600 2026-08-01