Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified CRITICAL 9.8
CVE-2025-66390

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an at…

No fix yet
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16407

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

Fix: 140.13.0 / 153.0+
Fix from $2,300 2026-07-21
Firefox HIGH 8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16332

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16330

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

Patch available
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16324

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-62414

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 8.7
CVE-2026-60030

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.2
CVE-2026-46415

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to vers…

Patch available
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-12972

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-16201

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.5
CVE-2026-51083

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privilege…

No fix yet
Fix from $1,600 2026-07-17
Argo Workflows CRITICAL 9.9
CVE-2026-54526

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow…

Fix: 3.7.15 / 4.0.6+
Fix from $2,300 2026-07-16
Unclassified HIGH 8.1
CVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUr…

Patch available
Fix from $1,950 2026-07-16
Dfx Server MEDIUM 6.3
CVE-2026-35148

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form…

Fix: after 2.5
Fix from $1,600 2026-07-16
Build Of Keycloak HIGH 8.1
CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.8
CVE-2026-62314

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.…

Patch available
Fix from $1,600 2026-07-15
Unclassified HIGH 8.5
CVE-2026-55234

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-45313

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.2
CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…

Mitigation only
Fix from $2,300 2026-07-15
Roomos HIGH 8.8
CVE-2026-20150

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…

Fix: 11.32.6.0 / 11.39.1.1+
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-47164

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only…

Patch available
Fix from $1,950 2026-07-15