Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified CRITICAL 9.8
CVE-2026-26292

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration tran…

Patch available
Fix from $2,300 2026-07-03
Unclassified HIGH 7.5
CVE-2026-27660

Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 8.1
CVE-2026-22555

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can ex…

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-24451

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no…

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-24690

Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-25712

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

Patch available
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-20706

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-20896EPSS 62%

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user w…

Patch available
Fix from $2,300 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-20909

Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.

Patch available
Fix from $1,600 2026-07-03
Build Of Keycloak MEDIUM 5.4
CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-07-03
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Unifi Dream Machine Pro Firmware HIGH 8.8
CVE-2026-55112

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability f…

Fix: after 5.1.15
Fix from $1,950 2026-07-02
Unifi Network Application HIGH 8.8
CVE-2026-55114

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Applica…

Fix: 10.4.57+
Fix from $1,950 2026-07-02
Unifi Connect CRITICAL 9.8
CVE-2026-55116

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…

Fix: 3.4.20+
Fix from $2,300 2026-07-02
Unifi Network Application HIGH 8.3
CVE-2026-55118

A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found…

Fix: 10.4.57+
Fix from $1,950 2026-07-02
Unifi Talk Application HIGH 8.1
CVE-2026-55119

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Applicatio…

Fix: 5.2.2+
Fix from $1,950 2026-07-02
Unifi Protect HIGH 8.6
CVE-2026-54407

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…

Fix: 7.1.83+
Fix from $1,950 2026-07-02
Unifi Protect CRITICAL 9.8
CVE-2026-54408

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…

Fix: 7.1.83+
Fix from $2,300 2026-07-02
Unifi Access CRITICAL 9.1
CVE-2026-54400

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica…

Fix: 4.2.29+
Fix from $2,300 2026-07-02
Unifi Connect Application CRITICAL 10.0
CVE-2026-50746

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C…

Fix: 3.24.20+
Fix from $2,300 2026-07-02
Mlflow HIGH 8.1
CVE-2026-8147

In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allo…

Fix: 3.14.0+
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.0
CVE-2026-50280

Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoin…

Patch available
Fix from $1,600 2026-07-02
Chrome MEDIUM 6.5
CVE-2026-14155

Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14156

Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14061

Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fr…

Fix: 150.0.7871.46+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14035

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive inform…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13954

Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13964

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrict…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13949

Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensit…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13953

Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30