Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified MEDIUM 5.3
CVE-2025-69727

An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPho…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4220

A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the fil…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4221

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage o…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4201

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of …

Mitigation only
Fix from $1,950 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4194

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-3…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4191

A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Pi…

Mitigation only
Fix from $1,950 2026-03-16
Dir 823g Firmware HIGH 7.5
CVE-2026-4193

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetD…

No fix yet
Fix from $1,950 2026-03-16
Dir 816 Firmware CRITICAL 9.8
CVE-2026-4180

A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goa…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified MEDIUM 6.9
CVE-2026-3111

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxA…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 8.7
CVE-2026-3110

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_est…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.1
CVE-2026-32720

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).…

Mitigation only
Fix from $1,950 2026-03-16
Cics Transaction Gateway HIGH 7.1
CVE-2026-0977

IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.7
CVE-2026-4105

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the cla…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified HIGH 8.2
CVE-2026-32138

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vul…

Mitigation only
Fix from $1,950 2026-03-12
Veeam Backup \& Replication HIGH 8.8
CVE-2026-21666

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Fix: 12.3.2.4465+
Fix from $1,950 2026-03-12
Veeam Backup \& Replication HIGH 8.8
CVE-2026-21667

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Fix: 12.3.2.4465+
Fix from $1,950 2026-03-12
Chrome MEDIUM 6.5
CVE-2026-3934

Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a …

Fix: 146.0.7680.71+
Fix from $1,600 2026-03-11
Chrome MEDIUM 5.3
CVE-2026-3939

Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a craf…

Fix: 146.0.7680.71+
Fix from $1,600 2026-03-11
Chrome MEDIUM 5.3
CVE-2026-3940

Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a…

Fix: 146.0.7680.71+
Fix from $1,600 2026-03-11
Chrome HIGH 7.5
CVE-2026-3932

Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Winter CRITICAL 9.9
CVE-2026-27591

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al…

Fix: 1.0.477 / 1.1.12+
Fix from $2,300 2026-03-11
Olivetin MEDIUM 6.5
CVE-2026-32102

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e…

Fix: after 3000.10.2
Fix from $1,600 2026-03-11
Unclassified CRITICAL 9.9
CVE-2025-66956

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachme…

Mitigation only
Fix from $2,300 2026-03-11
Alienware Command Center MEDIUM 5.5
CVE-2026-24509

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with l…

Fix: 6.12.24.0+
Fix from $1,600 2026-03-11
Taskosaur CRITICAL 9.8
CVE-2026-31874

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly…

Patch available
Fix from $2,300 2026-03-11
Parse Server HIGH 7.5
CVE-2026-31872

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protec…

Fix: 8.6.32 / 9.6.0+
Fix from $1,950 2026-03-11
Unclassified HIGH 8.8
CVE-2025-68623

In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process,…

Mitigation only
Fix from $1,950 2026-03-11
Open Forms MEDIUM 6.5
CVE-2026-28803

Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instruc…

Fix: 3.3.13 / 3.4.5+
Fix from $1,600 2026-03-11
Umbraco Cms HIGH 7.2
CVE-2026-31834

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under ce…

Fix: 16.5.1 / 17.2.2+
Fix from $1,950 2026-03-10
Unicorn MEDIUM 5.3
CVE-2026-31815

Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-un…

Fix: 0.67.0+
Fix from $1,600 2026-03-10