Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Teamwork Management System CRITICAL 9.8
CVE-2026-1061

A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/…

Fix: after 2.28.0
Fix from $2,300 2026-01-17
Altium Live MEDIUM 5.4
CVE-2026-1009

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An …

Mitigation only
Fix from $1,600 2026-01-15
Pimcore MEDIUM 6.5
CVE-2026-23494

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side aut…

Fix: 11.5.14 / 12.3.1+
Fix from $1,600 2026-01-15
Web2print Tools MEDIUM 5.4
CVE-2026-23496

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se…

Fix: 5.2.2 / 6.1.1+
Fix from $1,600 2026-01-15
Unclassified HIGH 8.8
CVE-2025-61973

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can repla…

Mitigation only
Fix from $1,950 2026-01-15
Glpi HIGH 7.5
CVE-2025-64516

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any …

Fix: 10.0.21 / 11.0.3+
Fix from $1,950 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22909

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential…

Mitigation only
Fix from $2,300 2026-01-15
Weblate HIGH 7.5
CVE-2026-21889

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access contro…

Fix: 5.15.2+
Fix from $1,950 2026-01-14
Unclassified HIGH 8.5
CVE-2025-14338

Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same i…

Mitigation only
Fix from $1,950 2026-01-14
N8n MEDIUM 5.3
CVE-2025-68949

n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string …

Fix: 2.2.0+
Fix from $1,600 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20949

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

No fix yet
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20929

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20839

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20843

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Server 2008 HIGH 7.5
CVE-2026-0386

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Firefox CRITICAL 10.0
CVE-2026-0881

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $2,300 2026-01-13
Label Studio MEDIUM 5.4
CVE-2026-22033

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e…

Fix: after 1.22.0
Fix from $1,600 2026-01-12
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15503

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
macOS MEDIUM 5.5
CVE-2025-46297

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files…

Fix: 26.2+
Fix from $1,600 2026-01-09
Simple Php Cms HIGH 7.2
CVE-2025-15495

A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the…

No fix yet
Fix from $1,950 2026-01-09
Ks Wr3600 Firmware HIGH 8.4
CVE-2025-68716

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with …

Mitigation only
Fix from $1,950 2026-01-08
Rustfs CRITICAL 9.8
CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…

Mitigation only
Fix from $2,300 2026-01-08
Titra HIGH 8.1
CVE-2026-21694

Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other u…

Fix: 0.99.50+
Fix from $1,950 2026-01-08
Librechat MEDIUM 5.9
CVE-2025-69220

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file co…

Patch available
Fix from $1,600 2026-01-07
House Rental And Property Listing Project CRITICAL 9.8
CVE-2026-0643

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified MEDIUM 6.4
CVE-2025-0980

Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid val…

Mitigation only
Fix from $1,600 2026-01-07
Unifi Connect Ev Station Lite Firmware MEDIUM 6.5
CVE-2026-21635

An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a…

Fix: 1.6.1+
Fix from $1,600 2026-01-05
Javamall CRITICAL 9.8
CVE-2025-15448

A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/m…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0577

A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-01-04
Bagisto HIGH 7.1
CVE-2026-21447

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde…

Fix: 2.3.10+
Fix from $1,950 2026-01-02