Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Webcenter Enterprise Capture CRITICAL 9.9
CVE-2026-35281

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Enterprise Capture CRITICAL 9.9
CVE-2026-35282

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Enterprise Capture CRITICAL 9.9
CVE-2026-35283

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Enterprise Capture CRITICAL 9.9
CVE-2026-35284

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Enterprise Capture CRITICAL 9.9
CVE-2026-35285

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are…

Mitigation only
Fix from $2,300 2026-06-17
Identity Manager CRITICAL 9.9
CVE-2026-35268

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and…

Mitigation only
Fix from $2,300 2026-06-17
Identity Manager HIGH 7.5
CVE-2026-35269

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12…

Mitigation only
Fix from $1,950 2026-06-17
Webcenter Content CRITICAL 9.1
CVE-2026-35270

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

Mitigation only
Fix from $2,300 2026-06-17
Peoplesoft Enterprise Pt Peopletools HIGH 8.7
CVE-2026-35271

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected a…

Mitigation only
Fix from $1,950 2026-06-17
Vm Virtualbox HIGH 7.5
CVE-2026-35275

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7…

Mitigation only
Fix from $1,950 2026-06-17
Data Integrator HIGH 8.3
CVE-2026-35262

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are …

Mitigation only
Fix from $1,950 2026-06-17
Weblogic Server CRITICAL 9.9
CVE-2026-35263

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and …

Mitigation only
Fix from $2,300 2026-06-17
Wasmtime HIGH 7.5
CVE-2026-47261

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FileP…

Fix: 24.0.9 / 36.0.10+
Fix from $1,950 2026-06-15
Unclassified HIGH 8.1
CVE-2026-50891

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-50892

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 8.1
CVE-2026-50881

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator an…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-50884

Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints v…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.1
CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.1
CVE-2026-50875

Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or del…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified MEDIUM 6.8
CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-5230

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-12203

A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/a…

Patch available
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-53520

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenti…

Mitigation only
Fix from $1,600 2026-06-12
Discourse MEDIUM 5.4
CVE-2026-44783

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-47182

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-44976

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue h…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-44208

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint a…

Mitigation only
Fix from $1,600 2026-06-12
Nuxt MEDIUM 5.3
CVE-2026-47200

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nit…

Fix: 3.21.6 / 4.4.6+
Fix from $1,600 2026-06-12