Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.1
CVE-2026-27708

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-56257

Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-bra…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-56302

Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.9
CVE-2026-47279

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied c…

Mitigation only
Fix from $1,600 2026-06-23
Traefik HIGH 7.1
CVE-2026-54761

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway…

Fix: 3.6.21 / 3.7.5+
Fix from $1,950 2026-06-23
Open Webui HIGH 8.3
CVE-2026-54010

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Open Webui HIGH 7.1
CVE-2026-54012

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Open Webui MEDIUM 6.4
CVE-2026-54015

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-histor…

Fix: 0.9.6+
Fix from $1,600 2026-06-23
Caddy HIGH 7.5
CVE-2026-52844

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outsid…

Fix: 2.11.4+
Fix from $1,950 2026-06-23
Deno MEDIUM 6.5
CVE-2026-49411

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the orig…

Fix: 2.8.0+
Fix from $1,600 2026-06-23
N8n CRITICAL 9.9
CVE-2026-54305

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature…

Fix: 1.123.55 / 2.25.7+
Fix from $2,300 2026-06-23
Unclassified MEDIUM 5.4
CVE-2026-44958

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such perm…

Mitigation only
Fix from $1,600 2026-06-23
Snowflake HIGH 8.1
CVE-2026-28381

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files…

Fix: after 1.14.12
Fix from $1,950 2026-06-22
Unclassified HIGH 7.5
CVE-2026-56253

Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attack…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12786

A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12782

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12784

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the compon…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12781

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the …

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12778

A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the c…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12779

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the co…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.8
CVE-2026-12780

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Dr…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.5
CVE-2026-56082

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_b…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 8.7
CVE-2026-4026

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 7.1
CVE-2026-4027

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to …

Mitigation only
Fix from $1,950 2026-06-19
Server Hardware Manager HIGH 7.8
CVE-2026-46461

Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access…

Fix: 3.2.2+
Fix from $1,950 2026-06-19
Dynamics 365 CRITICAL 9.9
CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-18
Unclassified HIGH 7.6
CVE-2026-46699

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to v…

Patch available
Fix from $1,950 2026-06-18
Node.js HIGH 8.2
CVE-2026-48617

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality …

Fix: after 26.3.0
Fix from $1,950 2026-06-18
Unclassified MEDIUM 6.9
CVE-2026-54533

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other …

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 7.3
CVE-2026-12529

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown fu…

Mitigation only
Fix from $1,950 2026-06-17