Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Joomla\! CRITICAL 9.8
CVE-2026-48899

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35223

An improper access check allows unauthorized access to com_config webservice endpoints.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-43934

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized …

Patch available
Fix from $1,600 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9495

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently droppe…

Patch available
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9517

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9445

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified HIGH 7.3
CVE-2026-9421

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the compo…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified HIGH 8.5
CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9412

A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Exec…

No fix yet
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9374

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the c…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 5.3
CVE-2026-9352

A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environm…

No fix yet
Fix from $1,600 2026-05-24
Unclassified MEDIUM 5.3
CVE-2026-9349

A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified HIGH 7.1
CVE-2026-39968

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …

Patch available
Fix from $1,950 2026-05-22
Elastic Cloud Storage HIGH 7.5
CVE-2022-31231

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attac…

Fix: 3.5.1.7 / 3.6.2.4+
Fix from $1,950 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Concrete Cms MEDIUM 5.3
CVE-2026-8240

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealin…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Mlflow MEDIUM 6.5
CVE-2026-2734

In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-…

Fix: 3.10.0+
Fix from $1,600 2026-05-21
Unclassified HIGH 8.6
CVE-2026-39310

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified HIGH 8.8
CVE-2026-44926

InfoScale CmdServer before 7.4.2 mishandles access control.

Mitigation only
Fix from $1,950 2026-05-20
Unclassified HIGH 7.8
CVE-2026-0856

Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified CRITICAL 10.0
CVE-2026-34234

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 8.1
CVE-2026-34358

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multip…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified MEDIUM 5.1
CVE-2026-34390

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient…

Patch available
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-34233

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints w…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified HIGH 7.3
CVE-2026-39250

An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfa…

Mitigation only
Fix from $1,950 2026-05-19
Build Of Keycloak MEDIUM 6.5
CVE-2026-37979

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 5.3
CVE-2026-31388

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.3
CVE-2026-32994

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any auth…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified CRITICAL 9.1
CVE-2023-24215

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator cred…

Mitigation only
Fix from $2,300 2026-05-18
Kilo Code Cli MEDIUM 6.5
CVE-2026-8766

A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of t…

Fix: after 7.0.47
Fix from $1,600 2026-05-17