Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 10 1607 HIGH 7.8
CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
macOS HIGH 8.8
CVE-2025-43524

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-12
Zulip Server MEDIUM 6.5
CVE-2026-40300

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/his…

No fix yet
Fix from $1,600 2026-05-12
Unclassified HIGH 8.8
CVE-2026-20887

Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged …

Mitigation only
Fix from $1,950 2026-05-12
macOS HIGH 7.5
CVE-2026-43652

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user …

Fix: 26.5+
Fix from $1,950 2026-05-11
Ipados MEDIUM 5.5
CVE-2026-28993

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados HIGH 7.5
CVE-2026-28974

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7,…

Fix: 15.7.7 / 26.5+
Fix from $1,950 2026-05-11
macOS HIGH 8.8
CVE-2026-28978

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados MEDIUM 5.5
CVE-2026-28988

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, wat…

Fix: 26.5+
Fix from $1,600 2026-05-11
Ipados HIGH 7.5
CVE-2026-28965

A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content fr…

Fix: 26.5+
Fix from $1,950 2026-05-11
macOS HIGH 7.5
CVE-2026-28930

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user …

Fix: 26.5+
Fix from $1,950 2026-05-11
macOS MEDIUM 6.5
CVE-2026-28922

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An ap…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Pgadmin 4 CRITICAL 9.9
CVE-2026-7813

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. M…

Fix: 9.15+
Fix from $2,300 2026-05-11
Identity Server HIGH 7.2
CVE-2025-9973

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication …

Fix: 7.1.0.26+
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.4
CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access…

Patch available
Fix from $2,300 2026-05-09
Unclassified MEDIUM 6.8
CVE-2026-1749

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permi…

Mitigation only
Fix from $1,600 2026-05-09
Unclassified HIGH 8.8
CVE-2026-42205

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in th…

Mitigation only
Fix from $1,950 2026-05-08
Langfuse MEDIUM 5.4
CVE-2026-41487

Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access co…

Fix: 3.167.0+
Fix from $1,600 2026-05-08
Dapr HIGH 8.1
CVE-2026-41491

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-…

Fix: 1.15.14 / 1.16.14+
Fix from $1,950 2026-05-08
Nitrosense HIGH 7.8
CVE-2026-8069

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use…

Fix: 3.00.3198 / 3.01.3056+
Fix from $1,950 2026-05-08
Pfsense CRITICAL 9.9
CVE-2025-69691

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only …

Mitigation only
Fix from $2,300 2026-05-08
Unclassified HIGH 8.8
CVE-2026-42278

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a crit…

Patch available
Fix from $1,950 2026-05-08
Nuclei MEDIUM 5.5
CVE-2026-41646

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScrip…

Fix: 3.8.0+
Fix from $1,600 2026-05-08
Openlearnx CRITICAL 10.0
CVE-2026-41900

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was…

Patch available
Fix from $2,300 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-8127

A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users…

Mitigation only
Fix from $1,600 2026-05-08
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Snipe It CRITICAL 9.8
CVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to …

Fix: 8.4.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile HIGH 8.8
CVE-2026-5786EPSS 6%

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to ga…

Fix: 12.6.1.1+
Fix from $1,950 2026-05-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-5788

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07