Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cognix Platform HIGH 8.1
CVE-2026-26417

A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated …

Mitigation only
Fix from $1,950 2026-03-05
Cognix Platform HIGH 7.5
CVE-2026-26418

Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access appli…

Mitigation only
Fix from $1,950 2026-03-05
Linux Enterprise Server CRITICAL 9.8
CVE-2026-25702

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via…

Mitigation only
Fix from $2,300 2026-03-05
Chrome HIGH 8.8
CVE-2026-3541

Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a …

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $1,950 2026-03-04
Chrome HIGH 8.8
CVE-2026-3542

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $1,950 2026-03-04
Chrome HIGH 8.8
CVE-2026-3543

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acc…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $1,950 2026-03-04
Adaptive Security Appliance Software MEDIUM 5.8
CVE-2026-20073

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all…

Mitigation only
Fix from $1,600 2026-03-04
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2026-20007

A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticat…

Mitigation only
Fix from $1,600 2026-03-04
Easyweb MEDIUM 6.5
CVE-2024-55025

Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI sy…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55019

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated att…

Mitigation only
Fix from $1,950 2026-03-03
Android MEDIUM 6.2
CVE-2026-0012

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Android HIGH 8.4
CVE-2025-48619

In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the…

Mitigation only
Fix from $1,950 2026-03-02
Sqlbot MEDIUM 6.3
CVE-2025-15597

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of t…

Fix: 1.5.0+
Fix from $1,600 2026-03-02
Initiative HIGH 7.5
CVE-2026-28276

Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded…

Fix: 0.32.2+
Fix from $1,950 2026-02-26
Steve MEDIUM 6.3
CVE-2026-28230

SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message…

Fix: after 3.11.0
Fix from $1,600 2026-02-26
Hoppscotch CRITICAL 9.1
CVE-2026-28215

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…

Fix: 2026.2.0+
Fix from $2,300 2026-02-26
Discourse MEDIUM 5.4
CVE-2026-28218

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugi…

Fix: 2025.12.2 / 2026.1.1+
Fix from $1,600 2026-02-26
Unclassified HIGH 7.5
CVE-2026-27449

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified MEDIUM 5.3
CVE-2026-2356

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj…

Mitigation only
Fix from $1,600 2026-02-26
Ajenti CRITICAL 9.8
CVE-2026-27975

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…

Fix: 2.2.13+
Fix from $2,300 2026-02-26
Unclassified MEDIUM 6.3
CVE-2026-3209

A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component…

Patch available
Fix from $1,600 2026-02-25
Sz Boot Parent CRITICAL 9.8
CVE-2026-3187

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api…

Fix: after 0.9.0
Fix from $2,300 2026-02-25
Coturn MEDIUM 6.5
CVE-2026-27624

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denie…

Fix: 4.9.0+
Fix from $1,600 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-24896

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Cont…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Gcom Epon 1ge Firmware HIGH 8.8
CVE-2025-63409

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settin…

Mitigation only
Fix from $1,950 2026-02-24
Firefox CRITICAL 10.0
CVE-2026-2768

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird …

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Imagemagick HIGH 7.8
CVE-2026-25966

ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule i…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
Smart Heating Integrated Management Platform CRITICAL 9.8
CVE-2026-3025

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2026-02-23
Student Result Management System CRITICAL 9.8
CVE-2026-2983

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin…

Mitigation only
Fix from $2,300 2026-02-23
Fastapiadmin HIGH 8.8
CVE-2026-2979

A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/modu…

Fix: after 2.2.0
Fix from $1,950 2026-02-23