Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 10 1607 HIGH 7.8
CVE-2026-41092

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Fortiportal MEDIUM 6.5
CVE-2026-49938

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions ma…

Fix: 7.2.9 / 7.4.8+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.2
CVE-2026-41984

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.1
CVE-2026-41985

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 5.3
CVE-2026-41847

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 throu…

Fix: 5.3.49+
Fix from $1,600 2026-06-09
Spring Hateoas HIGH 7.5
CVE-2026-41006

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs be…

Fix: 1.5.7 / 2.3.5+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.3
CVE-2026-11532

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function …

Mitigation only
Fix from $1,600 2026-06-08
Flowise CRITICAL 9.6
CVE-2026-46441

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise CRITICAL 9.6
CVE-2026-42861

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise MEDIUM 5.0
CVE-2026-42862

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,600 2026-06-08
Flowise HIGH 8.1
CVE-2026-42863

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Unclassified HIGH 7.3
CVE-2026-11474

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown func…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.4
CVE-2026-11466

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/ag…

Patch available
Fix from $1,600 2026-06-07
Unclassified MEDIUM 5.3
CVE-2026-11458

A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,600 2026-06-07
Termix CRITICAL 9.0
CVE-2026-45746

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manage…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Unclassified HIGH 7.3
CVE-2026-11344

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-11333

A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dc…

Mitigation only
Fix from $1,600 2026-06-05
Jce CRITICAL 9.8
CVE-2026-48907 KEVEPSS 69%

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in …

Fix: 2.9.99.5+
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.0
CVE-2026-11326

OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in for…

Mitigation only
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11275

Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the render…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11258

Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage i…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11210

Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access contro…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11204

Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11190

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11193

Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11197

Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.3
CVE-2026-11187

Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafte…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome HIGH 8.8
CVE-2026-11179

Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML pag…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11135

Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11078

Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04