Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Chrome MEDIUM 6.5
CVE-2026-13932

Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 5.3
CVE-2026-13933

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proce…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13936

Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitiv…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13937

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proce…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13931

Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer p…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 5.5
CVE-2026-13914

Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive inf…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome HIGH 8.8
CVE-2026-13897

Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome HIGH 8.1
CVE-2026-13864

Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious ext…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13828

Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive informat…

Fix: 150.0.7871.46+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13818

Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a c…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome HIGH 7.8
CVE-2026-13800

Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege esc…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Mantaray Nm MEDIUM 6.5
CVE-2025-24816

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could…

Fix: 25R2-NM+
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-51221

A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via su…

Mitigation only
Fix from $1,950 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43713

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari HIGH 7.1
CVE-2026-43701

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac…

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Helix3 HIGH 7.5
CVE-2026-49049EPSS 28%

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON file…

Fix: after 3.1.1
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13568

A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_hand…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13553

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13547

A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13544

A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. Thi…

Mitigation only
Fix from $1,600 2026-06-29
Budibase HIGH 7.3
CVE-2026-50132

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)…

Fix: 3.39.0+
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-56823

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.0
CVE-2026-48529

GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCac…

Mitigation only
Fix from $1,600 2026-06-26
Node.js MEDIUM 5.4
CVE-2026-48928

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supporte…

Patch available
Fix from $1,600 2026-06-26
Node.js CRITICAL 9.8
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve…

Patch available
Fix from $2,300 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-56050

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…

No fix yet
Fix from $1,600 2026-06-25
Display And Peripheral Manager HIGH 7.8
CVE-2026-46733

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacke…

Fix: 2.3.0+
Fix from $1,950 2026-06-25
Nsd HIGH 7.5
CVE-2026-12490

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-52810

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service …

Patch available
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-31978

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ar…

Mitigation only
Fix from $1,600 2026-06-24