Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.3
CVE-2026-8758

A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp.…

Mitigation only
Fix from $1,950 2026-05-17
H2o MEDIUM 5.3
CVE-2026-8752

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapid…

Fix: after 7402
Fix from $1,600 2026-05-17
H2o HIGH 7.5
CVE-2026-8750

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water…

Fix: after 7402
Fix from $1,950 2026-05-17
Open Webui HIGH 8.1
CVE-2026-45301

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all…

Fix: 0.3.16+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-44556

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the Ope…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Traefik CRITICAL 9.9
CVE-2026-44774

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant wi…

Fix: 2.11.46 / 3.6.17+
Fix from $2,300 2026-05-15
Unclassified MEDIUM 6.5
CVE-2025-67437

Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.

No fix yet
Fix from $1,600 2026-05-15
Unclassified HIGH 8.8
CVE-2024-36323

Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to th…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 8.5
CVE-2026-7373

Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When st…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified MEDIUM 5.3
CVE-2025-0040

Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical acce…

Mitigation only
Fix from $1,600 2026-05-15
Chrome MEDIUM 5.5
CVE-2026-8586

Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control v…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Cfengine MEDIUM 5.3
CVE-2026-24711

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.

Fix: 3.21.8 / 3.24.3+
Fix from $1,600 2026-05-14
Unclassified HIGH 7.5
CVE-2026-44478

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboard…

Mitigation only
Fix from $1,950 2026-05-13
Grafana HIGH 7.1
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t…

Fix: 11.6.14 / 12.2.8+
Fix from $1,950 2026-05-13
Grafana HIGH 8.1
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The …

Fix: 11.6.14 / 12.2.8+
Fix from $1,950 2026-05-13
Vm2 CRITICAL 9.1
CVE-2026-44007

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require(…

Fix: 3.11.1+
Fix from $2,300 2026-05-13
T18 21k Firmware MEDIUM 6.8
CVE-2026-36738

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks a…

No fix yet
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.3
CVE-2026-44341

GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job detai…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-44352

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Bro…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every …

Mitigation only
Fix from $2,300 2026-05-12
Fortiauthenticator CRITICAL 9.8
CVE-2026-44277

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…

Fix: 6.5.7 / 6.6.9+
Fix from $2,300 2026-05-12
Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Excel MEDIUM 5.5
CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-42177

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a s…

Mitigation only
Fix from $1,600 2026-05-12
365 Copilot MEDIUM 6.2
CVE-2026-41614

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Fix: 19.2604.43111.0+
Fix from $1,600 2026-05-12
Word MEDIUM 5.5
CVE-2026-41101

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
Powerpoint MEDIUM 5.5
CVE-2026-41102

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
365 Apps HIGH 8.8
CVE-2026-40420

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows Admin Center HIGH 8.8
CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2.6.7+
Fix from $1,950 2026-05-12
Azure Connected Machine Agent HIGH 7.8
CVE-2026-40381

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.63+
Fix from $1,950 2026-05-12