Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Reviactyl CRITICAL 9.8
CVE-2026-34456

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before …

Patch available
Fix from $2,300 2026-04-01
Joomla\! HIGH 8.8
CVE-2026-23899

An improper access check allows unauthorized access to webservice endpoints.

Fix: 5.4.4 / 6.0.4+
Fix from $1,950 2026-04-01
Unclassified MEDIUM 6.3
CVE-2026-1879

A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of t…

Mitigation only
Fix from $1,600 2026-04-01
Joomla\! HIGH 7.3
CVE-2026-21629

The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd par…

Fix: 5.4.4 / 6.0.4+
Fix from $1,950 2026-04-01
Unclassified HIGH 7.3
CVE-2026-5261

A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base…

Mitigation only
Fix from $1,950 2026-04-01
Esign HIGH 7.1
CVE-2026-4947

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, t…

Fix: 2026-03-26+
Fix from $1,950 2026-04-01
Dnr 202l Firmware MEDIUM 5.3
CVE-2026-5215

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $1,600 2026-03-31
Avideo HIGH 7.3
CVE-2026-34733

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a …

Fix: after 26.0
Fix from $1,950 2026-03-31
Admidio HIGH 7.5
CVE-2026-34381

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny dire…

Fix: 5.0.8+
Fix from $1,950 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5181

A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file …

Mitigation only
Fix from $1,600 2026-03-31
Node.js MEDIUM 5.3
CVE-2026-21711

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, whil…

Fix: 20.0.0+
Fix from $1,600 2026-03-30
Awesome Llm Apps HIGH 8.2
CVE-2026-29872

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-…

No fix yet
Fix from $1,950 2026-03-30
Unclassified MEDIUM 6.5
CVE-2026-29597

DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive confi…

Mitigation only
Fix from $1,600 2026-03-30
Unclassified MEDIUM 5.3
CVE-2026-5003

A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the fil…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified HIGH 7.3
CVE-2026-5001

A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the f…

Mitigation only
Fix from $1,950 2026-03-28
Librechat MEDIUM 5.3
CVE-2026-31950

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:…

No fix yet
Fix from $1,600 2026-03-27
Unclassified MEDIUM 6.5
CVE-2025-69988

BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proximity can associate with this …

Mitigation only
Fix from $1,600 2026-03-27
Mytube CRITICAL 9.8
CVE-2026-33890

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitra…

Fix: 1.8.71+
Fix from $2,300 2026-03-27
Pinchtab HIGH 8.8
CVE-2026-33622

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary Ja…

Fix: after 0.8.5
Fix from $1,950 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55261

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…

Mitigation only
Fix from $2,300 2026-03-26
Unclassified MEDIUM 5.6
CVE-2026-4830

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php …

Mitigation only
Fix from $1,600 2026-03-26
Ipados HIGH 7.5
CVE-2026-28876

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, …

Fix: 14.8.5 / 15.7.5+
Fix from $1,950 2026-03-25
Ipados MEDIUM 6.5
CVE-2026-28880

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS …

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28862

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5,…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Ipados MEDIUM 6.5
CVE-2026-28863

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26…

Fix: 26.4+
Fix from $1,600 2026-03-25
Ipados HIGH 7.5
CVE-2026-28855

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able…

Fix: 26.3+
Fix from $1,950 2026-03-25
Ipados MEDIUM 6.2
CVE-2026-28833

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An …

Fix: 26.4+
Fix from $1,600 2026-03-25
macOS HIGH 7.5
CVE-2026-28837

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

Fix: 26.4+
Fix from $1,950 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28838

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28818

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An ap…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25