Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Nios HIGH 7.7
CVE-2025-61879

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

Fix: after 8.6.5
Fix from $1,950 2026-02-12
Unclassified CRITICAL 9.0
CVE-2025-69634

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified HIGH 7.8
CVE-2026-23856

Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, con…

Mitigation only
Fix from $1,950 2026-02-12
Ipados HIGH 7.1
CVE-2026-20628

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS …

Fix: 14.8.4 / 15.7.4+
Fix from $1,950 2026-02-11
Ipados MEDIUM 5.5
CVE-2026-20638

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned o…

Fix: 26.3+
Fix from $1,600 2026-02-11
Unclassified HIGH 7.5
CVE-2026-2250

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQ…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-8025

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified MEDIUM 6.9
CVE-2025-29939

Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secu…

Mitigation only
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Tapo C260 Firmware MEDIUM 6.5
CVE-2026-0653

On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchr…

Fix: 1.1.9+
Fix from $1,600 2026-02-10
Filerise HIGH 7.5
CVE-2026-25231

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerabil…

Fix: 3.3.0+
Fix from $1,950 2026-02-09
Douphp HIGH 7.2
CVE-2026-2226

A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File …

Fix: after 1.9
Fix from $1,950 2026-02-09
Online Music Site HIGH 7.2
CVE-2026-2213

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Adminis…

No fix yet
Fix from $1,950 2026-02-09
Certificate CRITICAL 9.8
CVE-2026-2183

A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This aff…

Fix: after 2017-10-16
Fix from $2,300 2026-02-08
E Commerce CRITICAL 9.8
CVE-2026-2164

A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/pr…

Mitigation only
Fix from $2,300 2026-02-08
Ac21 Firmware HIGH 7.5
CVE-2026-2148

A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the compo…

No fix yet
Fix from $1,950 2026-02-08
Ac21 Firmware MEDIUM 5.3
CVE-2026-2147

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Mana…

No fix yet
Fix from $1,600 2026-02-08
Yshopmall HIGH 8.8
CVE-2026-2146

A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar…

Fix: after 1.9.1
Fix from $1,950 2026-02-08
Online Music Site CRITICAL 9.8
CVE-2026-2133

A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCate…

Mitigation only
Fix from $2,300 2026-02-08
Wekan HIGH 8.8
CVE-2026-2206

A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of t…

Fix: 8.21+
Fix from $1,950 2026-02-08
Wekan MEDIUM 5.3
CVE-2026-2207

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c…

Fix: 8.21+
Fix from $1,600 2026-02-08
Warehouse HIGH 8.8
CVE-2026-2075

A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission o…

Fix: after 2025-10-06
Fix from $1,950 2026-02-07
Spree HIGH 7.5
CVE-2026-25758

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow th…

Fix: 4.10.3 / 5.0.8+
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2056

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /…

No fix yet
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2054

A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Ha…

No fix yet
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2055

A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Cli…

No fix yet
Fix from $1,950 2026-02-06
Gas Agency Management System MEDIUM 6.5
CVE-2026-2009

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/…

No fix yet
Fix from $1,600 2026-02-06
Azure Front Door CRITICAL 9.8
CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-02-05
Azure Arc CRITICAL 9.8
CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-02-05