Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Wger HIGH 7.6
CVE-2026-40474

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.ch…

Fix: 2.5+
Fix from $1,950 2026-04-17
Zrok MEDIUM 5.3
CVE-2026-40304

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contai…

Fix: 2.0.1+
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-6492

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an u…

Patch available
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.3
CVE-2026-6489

A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of th…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.5
CVE-2026-37100

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-31843

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthent…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified HIGH 7.5
CVE-2026-30994

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, inclu…

Mitigation only
Fix from $1,950 2026-04-15
Dynamics 365 MEDIUM 5.5
CVE-2026-33103

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

Fix: 9.1.44.15+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32214

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27914

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 7.8
CVE-2026-26183

Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
October MEDIUM 6.8
CVE-2026-22692

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vul…

Fix: 3.7.13 / 4.1.5+
Fix from $1,600 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-22564

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized chang…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified HIGH 7.5
CVE-2026-22566

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 …

Mitigation only
Fix from $1,950 2026-04-13
Unclassified MEDIUM 5.4
CVE-2026-6201

A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of th…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-31282

Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker…

Mitigation only
Fix from $2,300 2026-04-13
Harmonyos MEDIUM 6.5
CVE-2026-34860

Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

No fix yet
Fix from $1,600 2026-04-13
Fastgpt HIGH 8.1
CVE-2026-40252

FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access…

Fix: 4.14.10.4+
Fix from $1,950 2026-04-10
Control M\/managed File Transfer HIGH 7.5
CVE-2026-23782

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API ide…

Fix: after 9.0.22
Fix from $1,950 2026-04-10
Directus HIGH 8.8
CVE-2026-39942

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-cont…

Fix: 11.17.0+
Fix from $1,950 2026-04-09
Chrome MEDIUM 6.5
CVE-2026-5881

Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Chrome HIGH 8.8
CVE-2026-5863

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Zammad HIGH 7.5
CVE-2026-34723

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access th…

Fix: 6.5.4+
Fix from $1,950 2026-04-08
Zammad MEDIUM 5.7
CVE-2026-34248

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other'…

Mitigation only
Fix from $1,600 2026-04-08
Podman Desktop CRITICAL 9.1
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…

Fix: 1.26.2+
Fix from $2,300 2026-04-07
Mise HIGH 7.8
CVE-2026-35533

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local proje…

Fix: after 2026.4.5
Fix from $1,950 2026-04-07
Vite HIGH 7.5
CVE-2026-39364

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by se…

Fix: after 8.0.4
Fix from $1,950 2026-04-07
Genieacs HIGH 7.5
CVE-2025-56015

In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.

No fix yet
Fix from $1,950 2026-04-07
Orangehrm MEDIUM 5.4
CVE-2026-39346

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass dis…

Fix: 5.8.1+
Fix from $1,600 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-39339

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (…

Fix: 7.1.0+
Fix from $2,300 2026-04-07