Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Rest Data Services CRITICAL 10.0
CVE-2026-46840

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit…

Fix: after 26.1.0
Fix from $2,300 2026-05-28
Financials Common Modules HIGH 7.7
CVE-2026-46821

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
Iassets CRITICAL 9.9
CVE-2026-46822

Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Universal Work Queue CRITICAL 9.9
CVE-2026-46824

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported …

Fix: after 12.2.15
Fix from $2,300 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46827

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite HIGH 8.1
CVE-2026-46828

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
Rest Data Services CRITICAL 9.9
CVE-2026-46775

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili…

Fix: after 26.1.0
Fix from $2,300 2026-05-28
E Business Suite HIGH 7.4
CVE-2026-46818

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite CRITICAL 9.1
CVE-2026-46819

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions t…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Financials Common Modules HIGH 8.5
CVE-2026-46820

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
Rest Data Services HIGH 8.1
CVE-2026-35277

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili…

Fix: after 26.1.0
Fix from $1,950 2026-05-28
Unclassified HIGH 7.7
CVE-2026-45296

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-prov…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.6
CVE-2026-7862

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenti…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-32995

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a…

Patch available
Fix from $1,950 2026-05-28
Unclassified HIGH 8.5
CVE-2026-9789

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.3
CVE-2026-46416

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared U…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.4
CVE-2026-47269

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remote feature checks utmpx ut_add…

Patch available
Fix from $1,950 2026-05-27
Openshift Container Platform MEDIUM 6.5
CVE-2026-1933

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, …

Fix: 4.2.2+
Fix from $1,600 2026-05-27
Advanced Custom Fields HIGH 8.1
CVE-2026-48906

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

Fix: after 7.1.1
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.1
CVE-2026-49002

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system dat…

No fix yet
Fix from $2,300 2026-05-27
Bosh MEDIUM 5.0
CVE-2026-41704

AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response[…

Fix: 282.1.12+
Fix from $1,600 2026-05-27
macOS MEDIUM 5.5
CVE-2025-43451

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user…

Fix: 26.0+
Fix from $1,600 2026-05-26
macOS MEDIUM 5.5
CVE-2025-46307

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Fix: 26.0+
Fix from $1,600 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9580

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDep…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9581

A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation …

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9579

A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the com…

Mitigation only
Fix from $1,600 2026-05-26
Opencti HIGH 7.2
CVE-2026-44730

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escala…

Fix: 6.9.7+
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9562

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unkn…

Mitigation only
Fix from $1,950 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48904

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48898

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26