Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32084

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or…

No fix yet
Fix from $2,300 2026-07-27
macOS HIGH 8.2
CVE-2026-64737

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
macOS CRITICAL 9.8
CVE-2026-64738

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS So…

Fix: 14.8.8 / 15.7.8+
Fix from $2,300 2026-07-27
macOS MEDIUM 5.5
CVE-2026-64723

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
macOS CRITICAL 9.8
CVE-2026-64702

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.…

Fix: 14.8.8 / 15.7.8+
Fix from $2,300 2026-07-27
Safari MEDIUM 6.5
CVE-2026-43821

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPa…

Fix: 26.6+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43819

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive u…

Fix: 26.6+
Fix from $1,600 2026-07-27
macOS CRITICAL 9.8
CVE-2026-43779

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app ma…

Fix: 14.8.8 / 15.7.8+
Fix from $2,300 2026-07-27
macOS HIGH 8.6
CVE-2026-43760

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to …

Fix: 14.8.8 / 26.6+
Fix from $1,950 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43763

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
macOS HIGH 7.1
CVE-2026-28945

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
Unclassified HIGH 7.7
CVE-2026-12990

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run witho…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.5
CVE-2026-14235

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, maki…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.0
CVE-2026-17432

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-age…

No fix yet
Fix from $1,600 2026-07-26
Unclassified HIGH 8.5
CVE-2026-48034

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there …

No fix yet
Fix from $1,950 2026-07-24
Azure App Service For Linux CRITICAL 9.8
CVE-2026-58630

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 7.1
CVE-2026-9765

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can acce…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.8
CVE-2026-15704

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon…

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 5.1
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.5
CVE-2026-14603

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-12688

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic…

No fix yet
Fix from $1,600 2026-07-24
Azure Api Management HIGH 7.2
CVE-2026-35425

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.7
CVE-2026-65759

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment informatio…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.2
CVE-2026-65760

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.1
CVE-2026-65757

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose …

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.2
CVE-2026-65758

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.8
CVE-2026-64876

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consiste…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-64871

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not …

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2024-58330

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event d…

No fix yet
Fix from $1,950 2026-07-23
Platform Security For Java CRITICAL 9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22